VDB
EN

DRUPAL-CONTRIB-2026-106

상세

This module integrates Drupal Commerce with the CyberSource payment gateway.

The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.

This issue only affects the Secure Acceptance Hosted Checkout gateway integration.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Packagist:https://packages.drupal.org/8 / drupal/commerce_cybersource
최초 영향 버전: 0 수정 버전: 1.10.0

Upgrade drupal/commerce_cybersource to 1.10.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

참고