- πΊπ¦Ukraine AstonVictor
I'm closing it because the issue was created a long time ago without any further steps.
if you still need it then raise a new one.
thanks
This is not a security issue.
oEmbed allows us to easily embed content from other sites, but it's so easy that some users may not recognize the inherent risks of allowing unchecked HTML to be embedded on their Drupal site.
The module's current security strategy is whitelisting. Providers are disabled by default (except in the embed.ly module, which probably should change).
For the input filter, the ordering of the filter within the format can affect security. If the filter is the last one in the format, it will output embedded content as is. If the filter precedes the HTML filter, the embedded content will be filtered as if the user added it herself.
Proposal:
We're not suggesting that oEmbed is insecure, but we should be much more cautious about the potential. If someone enables this module, enables all providers, and allows all users to embed content, this might be a risk! If pastebin or tumblr has a vulnerability, an exploit might be transmitted to any site that can embed its content.
Closed: outdated
0.0
Documentation
I'm closing it because the issue was created a long time ago without any further steps.
if you still need it then raise a new one.
thanks