An XSRF vulnerability could force an aggregator feed to update. Since some services were rate-limited (e.g. Twitter limits requests to 150 per hour) this could lead to a denial of service.
Part of security release SA-CORE-2012-001
This vulnerability affects the following application versions:
- Drupal 7.0
- Drupal 7.1
- Drupal 7.2
- Drupal 7.3
- Drupal 7.4
- Drupal 7.5
- Drupal 7.6
- Drupal 7.7
- Drupal 7.8
- Drupal 7.9
- Drupal 7.10