
====================================================================

                              CERT-Renater

                 Note d'Information No. 2017/VULN095
_____________________________________________________________________

DATE                : 31/03/2017

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Office Hours for DRUPAL versions
                       prior to 7.x-1.6,
                     Linkit for DRUPAL versions prior to 8.x-4.3.

=====================================================================
https://www.drupal.org/node/2862985
https://www.drupal.org/node/2862986
____________________________________________________________________

Office Hours - Moderately Critical - Cross Site Scripting -
DRUPAL-SA-CONTRIB-2017-032
Posted by Drupal Security Team on March 22, 2017 at 4:37pm

    Advisory ID: DRUPAL-SA-CONTRIB-2017-032
    Project: Office Hours (third-party module)
    Version: 7.x
    Date: 2017-March-22
    Security risk: 10/25 ( Moderately Critical)
AC:Basic/A:Admin/CI:None/II:Some/E:Theoretical/TD:All
    Vulnerability: Cross Site Scripting

Description

This module enables you to show the office hours of a location to the
public.

The module doesn't sufficiently filter user input for malicious Cross
Site Scripting (xss).

This vulnerability is mitigated by the fact that an attacker must have
a role with a permission to add fields to an entity.

CVE identifier(s) issued

    A CVE identifier will be requested, and added upon issuance, in
accordance with Drupal Security Team processes.

Versions affected

    Office Hours 7.x-1.x versions prior to 7.x-1.6.

Drupal core is not affected. If you do not use the contributed Office
Hours module, there is nothing you need to do.


Solution

Install the latest version:

    If you use the Office Hours module for Drupal 7.x, upgrade to
office_hours 7.x-1.6

Also see the Office Hours project page.


Reported by

    Drupal_Jedi


Fixed by

    Drupal_Jedi
    John Voskuilen
    Dave Hall


Coordinated by

    Michael Hess of the Drupal Security Team


Contact and More Information

The Drupal security team can be reached at security at drupal.org or
via the contact form at https://www.drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing
secure code for Drupal, and securing your site.

Follow the Drupal Security Team on Twitter at https://twitter.com
/drupalsecurity

⋅ Categories: Drupal 7.x
____________________________________________________________________

Linkit - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-033
Posted by Drupal Security Team on March 22, 2017 at 4:40pm

    Advisory ID: DRUPAL-SA-CONTRIB-2017-033
    Project: Linkit- Enriched linking experience (third-party module)
    Version: 8.x
    Date: 2017-March-22
    Security risk: 10/25 ( Moderately Critical)
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Default
    Vulnerability: Access bypass


Description

Linkit provides an easy interface for internal and external linking
with WYSIWYG editors by using an autocomplete field.

When searching for entities, this module doesn't always enforce the
access restrictions and users may see information about entities they
should not be able to access.

This is mitigated by the fact that a user must have access to a text
format that uses Linkit.

CVE identifier(s) issued

    A CVE identifier will be requested, and added upon issuance, in
accordance with Drupal Security Team processes.


Versions affected

    Linkit 8.x-4.x versions prior to 8.x-4.3.

Drupal core is not affected. If you do not use the contributed Linkit-
Enriched linking experience module, there is nothing you need to do.


Solution

Install the latest version:

    If you use the Linkit module for Drupal 8.x, upgrade to Linkit
8.x-4.3

Also see the Linkit- Enriched linking experience project page.


Reported by

    Ben Dougherty of the Drupal Security Team


Fixed by

    Emil Stjerneman the module maintainer
    Ben Dougherty of the Drupal Security Team


Coordinated by

    Michael Hess of the Drupal Security Team


Contact and More Information

The Drupal security team can be reached at security at drupal.org or
via the contact form at https://www.drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing
secure code for Drupal, and securing your site.

Follow the Drupal Security Team on Twitter at

https://twitter.com/drupalsecurity


==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================


