Jsonapi Role Access
The module does not properly enforce access rules when a request mimics a specific type of background web request. A visitor could read hidden data feeds or change data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Jsonapi Role Access to 2.0.2.
For developers: what the fix changed
The fix removes the `isXmlHttpRequest()` check from the early return condition in `checkUserRoleAccess` within `src/EventSubscriber/CheckUserRolePermissionEvent.php`, ensuring that requests mimicking XMLHttpRequests cannot bypass role access restrictions.
Also in this release Added a functional test to verify that XMLHttpRequest headers cannot bypass role restrictions.
src/EventSubscriber/CheckUserRolePermissionEvent.php+6 −5 fix