CIVI-SA-2020-16: JQuery Security Update for CVE-2020-11022, CVE-2020-11023

Published
2020-08-19 09:00
Written by

The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the jQuery blog, both are

"[...] security issues in jQuery’s DOM manipulation methods, as in .html(), .append(), and the others. Security advisories for both of these issues have been published on GitHub."

Those advisories are:

CIVI-SA-2020-11: CSRF on CKEditor Configuration Form

Published
2020-08-19 09:00
Written by

CiviCRM did not provide sufficient protection on the CKEditor configuration form, which could allow a malicious third-party to trick a CiviCRM administrator into changing the configuration.

Note: This form had another vulnerability in the same version. The risk from two overlapping vulnerabilities may be greater than the risk of each individually.

CIVI-SA-2020-09: Privilege Escalation via ACL Smart Groups

Published
2020-08-19 09:00
Written by

In CiviCRM, an Access Control List (ACL) confers limited access to contact records (based on the membership list for a "Group" of contacts). In configurations with "ACL Smart Groups", a flaw allowed limited backend users to re-define their group criteria and gain elevated access. The fix ensures that only trusted users (with permission "edit groups") may re-define the group criteria.

Movement Communications Director

Published
2020-08-13 22:46
Written by

Summary
You are a community-centered leader ready to inspire the people who set knowledge free as a global movement
The Wikimedia Foundation is the non-profit organization that operates Wikipedia—serving nearly half a billion users every month—and its related knowledge projects. We are supported by a community of more than 250,000 global volunteers.

We’d like you to: