6.4

CVE-2012-1635

The hook_node_access function in the revisioning module 7.x-1.x before 7.x-1.3 for Drupal checks the permissions of the current user even when it is called to check permissions of other users, which allows remote attackers to bypass intended access restrictions, as demonstrated when using the XML sitemap module to obtain sensitive information about unpublished content.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rik De Boer ≫ Revisioning Version 7.x-1.0
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update alpha1
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update alpha2
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update alpha3
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update alpha4
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update alpha5
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta1
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta10
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta11
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta2
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta3
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta4
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta5
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta6
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta7
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta8
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.0 Update beta9
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.1
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.2
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.x
   Drupal ≫ Drupal Version -
Rik De Boer ≫ Revisioning Version 7.x-1.x Update dev
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.36% 0.681
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/04/07/1
http://drupal.org/node/1407456
Patch
https://drupal.org/node/1409268
Patch
Vendor Advisory