- Backdrop Core versions prior to 1.1.2
Open redirect (Field UI module)
The Field UI module uses a "destinations" query string parameter in URLs to redirect users to new destinations after completing an action on a few administration pages. Under certain circumstances, malicious users can use this parameter to construct a URL that will trick users into being redirected to a 3rd party website, thereby exposing the users to potential social engineering attacks. This vulnerability is mitigated by the fact that only sites with the Field UI module enabled are affected.
Information disclosure (Render cache system)
On sites utilizing Backdrop's render cache system to cache content on the site by user role, private content viewed by user 1 may be included in the cache and exposed to non-privileged users. This vulnerability is mitigated by the fact that render caching is not used in Backdrop core itself (it requires custom code to enable) and that it only affects sites that have user 1 browsing the live site. Exposure is also limited if an administrative role has been assigned to the user 1 account (which is done, for example, by the Standard install profile that ships with Backdrop core).
Upgrade your site to the latest version of Backdrop CMS. Download available at Backdrop CMS 1.1.2 release page. Update instructions are available at https://backdropcms.org/upgrade#from-previous-versions.
Open redirect in the Field UI module:
- Yves Chedemois, Drupal Field UI module maintainer
- Damien McKenna provisional member of the Drupal Security Team
- Pere Orga of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Klaus Purer of the Drupal Security Team
Information disclosure in the render cache system: