PT-2012-3400 · Drupal · Drupal

Kurt Seifried

·

Published

2012-08-28

·

Updated

2012-08-29

·

CVE-2012-1635

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal revisioning module versions 7.x-1.x before 7.x-1.3
Description The issue allows remote attackers to bypass intended access restrictions. This is demonstrated when using the XML sitemap module to obtain sensitive information about unpublished content, due to the hook node access function checking the permissions of the current user even when it is called to check permissions of other users.
Recommendations For Drupal revisioning module versions 7.x-1.x before 7.x-1.3, update to version 7.x-1.3 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1635

Affected Products

Drupal