Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpm6-h53m-x2xf

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Drupal improper access restrictions

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

Пакеты

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.14

7.14

EPSS

Процентиль: 63%
0.00461
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 12 лет назад

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

nvd
больше 12 лет назад

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

debian
больше 12 лет назад

Drupal 7.x before 7.14 does not properly restrict access to nodes in a ...

EPSS

Процентиль: 63%
0.00461
Низкий

Дефекты

CWE-284