Drupal Global Redirect 6.x / 7.x Open Redirect

2012-06-14 / 2012-08-15
Credit: Ben Johnson
Risk: Low
Local: No
Remote: Yes
CWE: CWE-601


CVSS Base Score: 5.8/10
Impact Subscore: 4.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: Partial

View online: http://drupal.org/node/1633054 * Advisory ID: DRUPAL-SA-CONTRIB-2012-103 * Project: Global Redirect [1] (third-party module) * Version: 6.x, 7.x * Date: 2012-June-13 * Security risk: Less critical [2] * Exploitable from: Remote * Vulnerability: Open Redirect -------- DESCRIPTION --------------------------------------------------------- This module improves SEO and usability of a site by redirecting visitors to user-friendly and search-engine-friendly URLs. The module does not sufficiently validate that a destination URL is internal to the site, allowing an attacker to disguise a malicious destination address as a query parameter passed to a legitimate site URL. This vulnerability is mitigated by the fact that a site must have the "non-clean to clean" redirect enabled; however, this is the default configuration. CVE: Requested -------- VERSIONS AFFECTED --------------------------------------------------- * Global Redirect 6.x-1.x versions prior to 6.x-1.4. * Global Redirect 7.x-1.x versions prior to 7.x-1.4. Drupal core is not affected. If you do not use the contributed Global Redirect [3] module, there is nothing you need to do. -------- SOLUTION ------------------------------------------------------------ Install the latest version: * If you use the Global Redirect module for Drupal 6.x, upgrade to Global Redirect 6.x-1.4 [4] * If you use the Global Redirect module for Drupal 7.x, upgrade to Global Redirect 7.x-1.4 [5] Also see the Global Redirect [6] project page. -------- REPORTED BY --------------------------------------------------------- * Ben Johnson [7] (benpjohnson) * Justin Klein-Keane [8] (Justin_KleinKeane) * Joe Chambers [9] (myrapunzeled) -------- FIXED BY ------------------------------------------------------------ * Nicholas Thompson [10] the module maintainer * Dave Reid [11] of the Drupal Security Team -------- COORDINATED BY ------------------------------------------------------ * Greg Knaddison [12] of the Drupal Security Team * Dave Reid [13] of the Drupal Security Team * Michael Hess [14] of the Drupal Security Team * Dylan Tack [15] of the Drupal Security Team * David Rothstein [16] of the Drupal Security Team -------- CONTACT AND MORE INFORMATION ---------------------------------------- The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [17]. Learn more about the Drupal Security team and their policies [18], writing secure code for Drupal [19], and securing your site [20]. [1] http://drupal.org/project/globalredirect [2] http://drupal.org/security-team/risk-levels [3] http://drupal.org/project/globalredirect [4] https://drupal.org/node/1378116 [5] https://drupal.org/node/1378118 [6] http://drupal.org/project/globalredirect [7] http://drupal.org/user/268889 [8] http://drupal.org/user/302225 [9] http://drupal.org/user/1228542 [10] http://drupal.org/user/59351 [11] http://drupal.org/user/53892 [12] http://drupal.org/user/36762 [13] http://drupal.org/user/53892 [14] http://drupal.org/user/102818 [15] http://drupal.org/user/96647 [16] http://drupal.org/user/124982 [17] http://drupal.org/contact [18] http://drupal.org/security-team [19] http://drupal.org/writing-secure-code [20] http://drupal.org/security/secure-configuration _______________________________________________ Security-news mailing list Security-news@drupal.org Unsubscribe at http://lists.drupal.org/mailman/listinfo/security-news _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

References:

http://drupal.org/node/1633054


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top