Plotly.js Graphing
An ordinary account on the site could write malicious data directly into a graph field. This could allow them to view or alter any information on the site including the underlying code.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if a person has access rights to edit a piece of content with a graph field and the site allows full edit access through a data feed or another direct method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Plotly.js Graphing to 3.0.2 or 4.0.0, whichever branch you are on.
For developers: what the fix changed
The fix prevents object injection by passing an array with allowed classes set to false to the unserialize function in PlotlyJsGraphFormatter.php and PlotlyJsGraphWidget.php. It also adds the serialized property names annotation to the PlotlyJsGraph field type in PlotlyJsGraph.php.
Also in this release Added a Drush 9 command to download the Plotly.js library and updated the README file.
README.md+2 −2drush.services.yml+8 −0src/Commands/PlotlyJsCommands.php+68 −0src/Plugin/Field/FieldFormatter/PlotlyJsGraphFormatter.php+2 −2 fixsrc/Plugin/Field/FieldType/PlotlyJsGraph.php+4 −0 fixsrc/Plugin/Field/FieldWidget/PlotlyJsGraphWidget.php+2 −2 fix