[3.4] drupal7: Multiple Vulnerabilities (no CVE)
CVE ID: not yet available
Saving user accounts can sometimes grant the user all roles
A vulnerability exists in the User module, where if some specific
contributed or custom code triggers a rebuild of the user profile
form,
a registered user can be granted all user roles on the site. This would
typically result in the user gaining administrative access.
This issue is mitigated by the fact that it requires contributed or custom code that performs a form rebuild during submission of the user profile form.
Views can allow unauthorized users to see Statistics information
An access bypass vulnerability exists in the Views module, where users
without the “View content count” permission
can see the number of hits collected by the Statistics module for
results in the view.
Affected versions:
- Drupal core 7.x versions prior to 7.44
- Drupal core 8.x versions prior to 8.1.3
Solution
- If you use Drupal 7.x, upgrade to Drupal core 7.44
- If you use Drupal 8.x, upgrade to Drupal core 8.1.3
Reference:
https://www.drupal.org/SA-CORE-2016-002
(from redmine: issue id 5746, created on 2016-06-19, closed on 2016-06-24)
- Relations:
- parent #5744 (closed)
- Changesets:
- Revision c9d8f8b9 on 2016-06-23T14:47:48Z:
community/drupal7: security upgrade to 7.44. Fixes #5746
(cherry picked from commit 9d0fa15cc4f29630f9813d9a438941a4f019774c)