Skip to content
This repository was archived by the owner on Dec 6, 2022. It is now read-only.

[GOVCMSD7-360] Update Services module to 7.x-3.27#971

Open
suhyeonh wants to merge 3 commits intogovCMS:7.x-3.xfrom
suhyeonh:GOVCMSD7-360
Open

[GOVCMSD7-360] Update Services module to 7.x-3.27#971
suhyeonh wants to merge 3 commits intogovCMS:7.x-3.xfrom
suhyeonh:GOVCMSD7-360

Conversation

@suhyeonh
Copy link
Contributor

Security Advisory - https://www.drupal.org/sa-contrib-2020-022
View online: https://www.drupal.org/sa-contrib-2020-022

Project: Services [1]
Version: 7.x-3.x-dev
Date: 2020-June-03
Security risk: Moderately critical 11∕25
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Description: 
This module provides a standardized solution for building API's so that
external clients can communicate with Drupal.

The module's taxonomy term index resource doesn't take into consideration
certain access control tags provided (but unused) by core, that certain
contrib modules depend on.

This vulnerability is mitigated by the fact your site must have the taxonomy
term index resource enabled, your site must have a contributed module enabled
which utilizes taxonomy term access control, and an attacker must know your
api endpoint's path.

Solution: 
Install the latest version:

@suhyeonh suhyeonh changed the title [GOVCMSD7-360] Update Services module to 7.x-3.26 [GOVCMSD7-360] Update Services module to 7.x-3.27 Jun 22, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants