SB2016111710 - Fedora 23 update for drupal7



SB2016111710 - Fedora 23 update for drupal7

Published: November 17, 2016 Updated: April 24, 2025

Security Bulletin ID SB2016111710
Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2016-9449)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.


2) Insufficient verification of data authenticity (CVE-ID: CVE-2016-9450)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.


3) Open redirect (CVE-ID: CVE-2016-9451)

The vulnerability allows a remote authenticated user to manipulate data.

Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.


4) Input validation error (CVE-ID: CVE-2016-9452)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.


Remediation

Install update from vendor's website.