Bugzilla – Bug 988896
VUL-0: CVE-2016-6211,CVE-2016-6212: drupal7, drupal8: several issues fixed in 7.44
Last modified: 2016-07-14 15:25:34 UTC
Courtesy bug from the SUSE security team for server:php:applications/drupal7 server:php:applications/drupal8 http://seclists.org/oss-sec/2016/q3/57 https://www.drupal.org/SA-CORE-2016-002 Saving user accounts can sometimes grant the user all roles (User module - Drupal 7 - Moderately Critical) A vulnerability exists in the User module, where if some specific contributed or custom code triggers a rebuild of the user profile form, a registered user can be granted all user roles on the site. This would typically result in the user gaining administrative access. Use CVE-2016-6211. https://www.drupal.org/SA-CORE-2016-002 https://www.drupal.org/node/2749333 Views can allow unauthorized users to see Statistics information (Views module - Drupal 8 - Less Critical) An access bypass vulnerability exists in the Views module, where users without the "View content count" permission can see the number of hits collected by the Statistics module for results in the view. The same vulnerability exists in the Drupal 7 Views module (see SA-CONTRIB-2016-036). Use CVE-2016-6212 for both the issue in Drupal Core and the issue in the Drupal 7 Views module. References: https://bugzilla.redhat.com/show_bug.cgi?id=1351214 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6211 http://seclists.org/oss-sec/2016/q3/57
Is fixed now. Update to 7.50