Tealium iQ Tag Management
An ordinary account on the site could write malicious data directly to a tracking field. They could view any hidden information on the website and alter any files including the underlying code.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has the access right to edit a piece of content with a Tealium field attached and the data feed module is set to accept all changes or the attacker has another way to edit field values directly.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Tealium iQ Tag Management to 8.x-2.4.
For developers: what the fix changed
The fix adds the `['allowed_classes' => FALSE]` option to `unserialize()` calls in `FieldItemNormalizer.php`, `TealiumiqFieldItem.php`, `TealiumiqWidget.php`, and `Helper.php` to prevent PHP object injection.
src/Normalizer/FieldItemNormalizer.php+1 −1 fixsrc/Plugin/Field/FieldType/TealiumiqFieldItem.php+1 −1 fixsrc/Plugin/Field/FieldWidget/TealiumiqWidget.php+1 −1 fixsrc/Service/Helper.php+1 −1 fix