SB2016112502 - Multiple vulnerabilities in Drupal



SB2016112502 - Multiple vulnerabilities in Drupal

Published: November 25, 2016 Updated: August 9, 2020

Security Bulletin ID SB2016112502
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2016-9452)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.


2) Insufficient verification of data authenticity (CVE-ID: CVE-2016-9450)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.


3) Information disclosure (CVE-ID: CVE-2016-9449)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.


Remediation

Install update from vendor's website.