Token Content Access
Someone could guess the special code by measuring how long the website takes to reply. They could then read hidden pieces of content protected by this module. They could not change any information on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if someone knows or finds the web address for the protected piece of content.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Token Content Access to 3.1.2.
For developers: what the fix changed
The fix replaces a standard string comparison with the timing safe hash_equals function in src/Access/TcaAccessCheck.php to prevent timing attacks, and limits the token length in tca.module.
Also in this release The release also refactors tca_form_alter in tca.module to use early returns and improve code readability.
src/Access/TcaAccessCheck.php+4 −4 fixtca.module+33 −18 fix