Freelinking - Moderately critical - Information Disclosure - SA-CONTRIB-2024-034

Джерело:
Security advisories for contributed projects

Дата публікації:
04/09/2024 18:35

Постійна адреса новини:
http://www.vsinovyny.com/11264075

Freelinking - Moderately critical - Information Disclosure - SA-CONTRIB-2024-034

 

04/09/2024 18:35 // Security advisories for contributed projects

Project: 
Date: 
2024-September-04
Security risk: 
Vulnerability: 
Information Disclosure
Affected versions: 
<4.0.1
Description: 

This module enables you to configure a wiki-like input filter that allows users to create links to site and external content.

The module doesn't sufficiently check if a user has access to some URLs before rendering them as links.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access content" (which is commonly assigned to all roles), and the site must be configured to disallow access to certain content.

Solution: 

Install the latest version:

  • If you use the freelinking module 4.0.x, upgrade to freelinking 4.0.1
  • If you use the freelinking module 8.x-3.x, upgrade to freelinking 4.0.1, as the 8.x-3.x branch is now unsupported
Reported By: 
Fixed By: 
Coordinated By: 

 

» Читати повністю

 

« Наступна новина з архіву
Content Entity Clone - Moderately critical - Information Disclosure - SA-CONTRIB-2024-035
  Попередня новина з архіву
В Україні змінили порядок страхування поїздок у транспорті: пасажир більше не сплачує
»

 

 
© 2026 www.vsinovyny.com