SB2016112502 - Multiple vulnerabilities in Drupal
Published: November 25, 2016 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2016-9452)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.
2) Insufficient verification of data authenticity (CVE-ID: CVE-2016-9450)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
3) Information disclosure (CVE-ID: CVE-2016-9449)
The vulnerability allows a remote authenticated user to gain access to sensitive information.
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
Remediation
Install update from vendor's website.