Bug 1347506

Summary: drupal7: Saving user accounts can sometimes grant the user all roles
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED DUPLICATE QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gwync, jsmith.fedora, peter.borsa, shawn, stickster
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: drupal 7.44.1 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-06-29 13:36:28 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1347507, 1347508    
Bug Blocks:    

Description Andrej Nemec 2016-06-17 06:34:28 UTC
A vulnerability exists in the User module, where if some specific contributed or custom code triggers a rebuild of the user profile form, a registered user can be granted all user roles on the site. This would typically result in the user gaining administrative access.

This issue is mitigated by the fact that it requires contributed or custom code that performs a form rebuild during submission of the user profile form.

External references:

https://www.drupal.org/SA-CORE-2016-002

Comment 1 Andrej Nemec 2016-06-17 06:35:11 UTC
Created drupal7 tracking bugs for this issue:

Affects: fedora-all [bug 1347507]
Affects: epel-all [bug 1347508]

Comment 2 Andrej Nemec 2016-06-29 13:36:28 UTC

*** This bug has been marked as a duplicate of bug 1351214 ***