REST & JSON API Authentication for Drupal
Anyone without logging in could bypass the security checks for some data feed requests. They could read private information from the data feed. They could not modify or delete any of that information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate REST & JSON API Authentication for Drupal to 3.2.0.
For developers: what the fix changed
The fix updates `RestAPI::applies()` in `src/Authentication/Provider/RestAPI.php` and `DisallowAPIRequests::check()` in `src/PageCache/DisallowAPIRequests.php` to use `$request->getPathInfo()` instead of `$request->getRequestUri()` for path matching. It also replaces a literal string check for `?_format=` with `$request->query->has('_format')` to prevent attackers from bypassing authentication by reordering query parameters.
Also in this release The release also added GitLab CI configuration and a new functional test.
.gitlab-ci.yml+18 −0src/Authentication/Provider/RestAPI.php+8 −3 fixsrc/PageCache/DisallowAPIRequests.php+2 −2 fix