PT-2012-3400 · Drupal · Drupal

Kurt Seifried

·

Publicado

2012-08-28

·

Atualizado

2012-08-29

·

CVE-2012-1635

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal revisioning module versions 7.x-1.x before 7.x-1.3
Description The issue allows remote attackers to bypass intended access restrictions. This is demonstrated when using the XML sitemap module to obtain sensitive information about unpublished content, due to the hook node access function checking the permissions of the current user even when it is called to check permissions of other users.
Recommendations For Drupal revisioning module versions 7.x-1.x before 7.x-1.3, update to version 7.x-1.3 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1635

Produtos afetados

Drupal