[Drupal] Media 7.x-2.19 and JSON_API 8.x / Critical

Little, Jason P. little.129 at osu.edu
Wed Apr 25 14:31:09 EDT 2018


In addition to the drupal core security update today, there was ALSO a critical update to media 7.x-2.x (and json_api for 8). 

Media is used by A TON of sites (~250k). It is around the 20th most popular for 7.x.

It looks like the media release hit d.org at 12:48p today our time.

Sooooo... be sure to check and see if you got media when you were updating earlier.

Best,
Jason

On 4/25/18, 2:10 PM, "Security-news on behalf of security-news at drupal.org" <security-news-bounces at drupal.org on behalf of security-news at drupal.org> wrote:

    View online: https://www.drupal.org/sa-contrib-2018-020
    
    Project: Media [1]
    Version: 7.x-2.18
    Date: 2018-April-25
    Security risk: *Critical* 18∕25
    AC:Basic/A:User/CI:All/II:All/E:Theoretical/TD:All [2]
    Vulnerability: Remote Code Execution
    
    Description: 
    The Media module provides an extensible framework for managing files and
    multimedia assets, regardless of whether they are hosted on your own site or
    a third party site.
    
    The module contained a vulnerability similar to SA-CORE-2018-004 [3], leading
    to a possible remote code execution (RCE) attack.
    
    Solution: 
    Install the latest version:
    
       * If you use the Media module for Drupal 7.x-2.x, upgrade to Media 7.x-2.19
         [4]
    
    Coordinated By: 
       * Dave Reid [5] the module maintainer and member of the Drupal Security 
    Team
    
    
    [1] https://www.drupal.org/project/media
    [2] https://www.drupal.org/security-team/risk-levels
    [3] https://www.drupal.org/sa-core-2018-004
    [4] https://www.drupal.org/project/media/releases/7.x-2.19
    [5] https://www.drupal.org/u/dave-reid
    
    _______________________________________________
    Security-news mailing list
    Security-news at drupal.org
    Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news
    



More information about the Drupal mailing list