Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-4wfq-jc9h-vpcx: Lack of domain validation in Druple core

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.

Drupal 7 core does not include the Media module and therefore is not affected.

ghsa
#xss#vulnerability#git#perl
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-25276

Lack of domain validation in Druple core

Moderate severity GitHub Reviewed Published Apr 26, 2023 to the GitHub Advisory Database • Updated Apr 26, 2023

Package

Affected versions

>= 8.0.0, < 9.3.19

>= 9.4.0, < 9.4.3

Patched versions

9.3.19

9.4.3

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.

Drupal 7 core does not include the Media module and therefore is not affected.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-25276
  • https://www.drupal.org/sa-core-2022-015

Published to the GitHub Advisory Database

Apr 26, 2023

Last updated

Apr 26, 2023

Related news

CVE-2022-25276: Drupal core - Moderately critical - Multiple vulnerabilities - SA-CORE-2022-015

The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of the primary domain. Under certain circumstances, this could lead to cross-site scripting, leaked cookies, or other vulnerabilities.

ghsa: Latest News

GHSA-hqmp-g7ph-x543: TunnelVision - decloaking VPNs using DHCP