Salesforce Suite
An ordinary account on the site could hijack the authorisation token and connect the website to their own Salesforce account. They could view restricted synchronisation details and modify certain contact records. They could not access or alter every piece of information on the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if it uses a version older than version six and has the Salesforce OAuth feature enabled with an active authorisation profile.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Salesforce Suite to 5.1.3.
For developers: what the fix changed
The fix adds a `state` parameter to the OAuth authorization request in `SalesforceOAuthPlugin::submitConfigurationForm` and validates it during the callback in `SalesforceOAuthController::oauthCallback` to prevent CSRF attacks.
Also in this release The release also includes PHP 8.3 compatibility fixes, updates to the JWT authentication plugin, enhancements to mapping and pull/push events, and various bug fixes.
.gitignore+3 −1.gitlab-ci.yml+2 −1composer.json+1 −1css/salesforce.css+1 −1modules/salesforce_example/src/EventSubscriber/SalesforceExampleSubscriber.php+3 −0modules/salesforce_jwt/composer.json+1 −1modules/salesforce_jwt/src/Consumer/JWTCredentials.php+41 −6modules/salesforce_jwt/src/Plugin/SalesforceAuthProvider/SalesforceJWTGovCloudPlugin.php+4 −22modules/salesforce_jwt/src/Plugin/SalesforceAuthProvider/SalesforceJWTPlugin.php+338 −29modules/salesforce_logger/salesforce_logger.services.yml+2 −0modules/salesforce_logger/src/Form/SettingsForm.php+6 −1modules/salesforce_mapping/config/schema/salesforce_mapping.schema.yml+8 −0