Skip to content
This repository has been archived by the owner on Dec 6, 2022. It is now read-only.

[GOVCMSD7-360] Update Services module to 7.x-3.27 #971

Open
wants to merge 3 commits into
base: 7.x-3.x
Choose a base branch
from
Open

[GOVCMSD7-360] Update Services module to 7.x-3.27 #971

wants to merge 3 commits into from

Conversation

suhyeonh
Copy link
Contributor

Security Advisory - https://www.drupal.org/sa-contrib-2020-022
View online: https://www.drupal.org/sa-contrib-2020-022

Project: Services [1]
Version: 7.x-3.x-dev
Date: 2020-June-03
Security risk: Moderately critical 11∕25
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Description: 
This module provides a standardized solution for building API's so that
external clients can communicate with Drupal.

The module's taxonomy term index resource doesn't take into consideration
certain access control tags provided (but unused) by core, that certain
contrib modules depend on.

This vulnerability is mitigated by the fact your site must have the taxonomy
term index resource enabled, your site must have a contributed module enabled
which utilizes taxonomy term access control, and an attacker must know your
api endpoint's path.

Solution: 
Install the latest version:

@suhyeonh suhyeonh changed the title [GOVCMSD7-360] Update Services module to 7.x-3.26 [GOVCMSD7-360] Update Services module to 7.x-3.27 Jun 22, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants