Project Browser
Anyone without logging in could trick an administrator into installing new features. They could view private site configurations and add unwanted modules to the site. They could not do this without tricking a logged in administrator.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Project Browser to 2.1.5 or 2.0.3, whichever branch you are on.
For developers: what the fix changed
Adds `_csrf_token: 'TRUE'` to the `project_browser.activate` and `project_browser.uninstall` routes in `project_browser.routing.yml` and introduces a `CsrfTokenPath` service to properly generate and inject CSRF tokens into URLs used by the frontend.
Also in this release Fixed an issue where an un-instantiable applied recipe would blank the entire catalog.
.cspell-project-words.txt+1 −0project_browser.routing.yml+2 −0 fixproject_browser.services.yml+3 −0 fixsrc/Activator/RecipeActivator.php+22 −2src/Controller/InstallerController.php+3 −21 fixsrc/CsrfTokenPath.php+58 −0 fixsrc/Element/ProjectBrowser.php+5 −0 fixsrc/ProjectBrowser/Normalizer.php+5 −1 fixsveltejs/public/build/bundle.js+0 −0sveltejs/public/build/bundle.js.map+0 −0sveltejs/src/InstallListProcessor.js+7 −5 fixsveltejs/src/constants.js+1 −0 fix