Exploit the possiblities

Drupal Media 7.x Access Bypass

Drupal Media 7.x Access Bypass
Posted Jan 9, 2014
Authored by Dave Reid, robearls | Site drupal.org

Drupal Media third party module version 7.x suffers from an access bypass vulnerability.

tags | advisory, bypass
MD5 | 02e1882b20f1f3b7f074a81b31a09ed4

Drupal Media 7.x Access Bypass

Change Mirror Download
View online: https://drupal.org/node/2169767

* Advisory ID: PSA-2014-001
* Project: Media [1] (third-party module)
* Version: 7.x
* Date: 2014-01-08
* Security risk: Moderately critical [2]
* Exploitable from: Remote
* Vulnerability: Access Bypass

-------- DESCRIPTION
---------------------------------------------------------

This is a public service announcement regarding the "import media"
permission, labeled as "Import media files from the local file system,"
provided by the Media module.

The Media module provides a method for Drupal administrators to import
existing files from an arbitrary location on the server. Users with the
'import media' permission can import any file from the server as local Drupal
files, even those outside the Drupal install directory, which could lead to
information disclosure.

As such, this permission should be granted to trusted site administrators. In
the 7.x-2.x version of the module, you may disable the sub-module named
"Media Bulk Upload" to disable this functionality.


-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------

* /A CVE identifier [3] will be requested, and added upon issuance, in
accordance with Drupal Security Team processes./

-------- VERSIONS AFFECTED
---------------------------------------------------

* Media module for Drupal 7.x

Drupal core is not affected. If you do not use the contributed Media [4]
module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

Only grant trusted site administrators the "import media" permission.

This permission is not marked as a restricted permission in the following
versions:

* Media module 7.x-1.x versions prior to 7.x-1.4 [5]
* Media module 7.x-2.x versions prior to 7.x-2.0-alpha3+37-dev

Upgrading to the latest release is recommended, but not required.

Also see the Media [6] project page.

-------- REPORTED BY
---------------------------------------------------------

* robearls [7]
* Dave Reid [8] of the Drupal Security Team

-------- FIXED BY
------------------------------------------------------------

* Dave Reid [9] the module maintainer and of the Drupal Security Team

-------- COORDINATED BY
------------------------------------------------------

* Dave Reid [10] the module maintainer and of the Drupal Security Team

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [11].

Learn more about the Drupal Security team and their policies [12], writing
secure code for Drupal [13], and securing your site [14].

Follow the Drupal Security Team on Twitter at
https://twitter.com/drupalsecurity [15]


[1] http://drupal.org/project/media
[2] http://drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] http://drupal.org/project/media
[5] https://drupal.org/node/2169795
[6] http://drupal.org/project/media
[7] https://drupal.org/user/2460638
[8] https://drupal.org/user/53892
[9] https://drupal.org/user/53892
[10] http://drupal.org/user/53892
[11] http://drupal.org/contact
[12] http://drupal.org/security-team
[13] http://drupal.org/writing-secure-code
[14] http://drupal.org/security/secure-configuration
[15] https://twitter.com/drupalsecurity

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

January 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    2 Files
  • 2
    Jan 2nd
    13 Files
  • 3
    Jan 3rd
    16 Files
  • 4
    Jan 4th
    39 Files
  • 5
    Jan 5th
    26 Files
  • 6
    Jan 6th
    40 Files
  • 7
    Jan 7th
    2 Files
  • 8
    Jan 8th
    16 Files
  • 9
    Jan 9th
    25 Files
  • 10
    Jan 10th
    28 Files
  • 11
    Jan 11th
    44 Files
  • 12
    Jan 12th
    32 Files
  • 13
    Jan 13th
    2 Files
  • 14
    Jan 14th
    4 Files
  • 15
    Jan 15th
    31 Files
  • 16
    Jan 16th
    15 Files
  • 17
    Jan 17th
    16 Files
  • 18
    Jan 18th
    24 Files
  • 19
    Jan 19th
    7 Files
  • 20
    Jan 20th
    0 Files
  • 21
    Jan 21st
    0 Files
  • 22
    Jan 22nd
    0 Files
  • 23
    Jan 23rd
    0 Files
  • 24
    Jan 24th
    0 Files
  • 25
    Jan 25th
    0 Files
  • 26
    Jan 26th
    0 Files
  • 27
    Jan 27th
    0 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close