An XSRF vulnerability could force an aggregator feed to update. Since some services were rate-limited (e.g. Twitter limits requests to 150 per hour) this could lead to a denial of service.

Part of security release SA-CORE-2012-001

This vulnerability affects the following application versions:

  • Drupal 7.0
  • Drupal 7.1
  • Drupal 7.2
  • Drupal 7.3
  • Drupal 7.4
  • Drupal 7.5
  • Drupal 7.6
  • Drupal 7.7
  • Drupal 7.8
  • Drupal 7.9
  • Drupal 7.10

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *