LWN.net Logo

drupal-cck: access bypass

Package(s):drupal-cck CVE #(s):
Created:June 22, 2010 Updated:October 14, 2010
Description: From the Drupal advisory:

The Content Construction Kit (CCK) project is a set of modules that allows you to add custom fields to nodes using a web browser.

The CCK "Node Reference" module can be configured to display referenced nodes as hidden, title, teaser or full view. Node access was not checked when displaying these which could expose view access on controlled nodes to unprivileged users.

In addition, Node Reference provides a backend URL that is used for asynchronous requests by the "autocomplete" widget to locate nodes the user can reference. This was not checking that the user had field level access to the source field, allowing direct queries to the backend URL to return node titles and IDs which the user would otherwise be unable to access. Note that as Drupal 5 CCK does not have any field access control functionality, this issue only applies to the Drupal 6 version.

Alerts:
Fedora FEDORA-2010-15707 2010-10-05
Fedora FEDORA-2010-15737 2010-10-05
Fedora FEDORA-2010-10127 2010-06-21
Fedora FEDORA-2010-10176 2010-06-21
Fedora FEDORA-2010-10200 2010-06-21

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds