The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://drupal.org/node/1619736 - Patch | |
References | () http://drupal.org/node/1619810 - Patch, Vendor Advisory | |
References | () http://drupalcode.org/project/og.git/commitdiff/1485708 - Exploit, Patch | |
References | () http://secunia.com/advisories/49397 - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2012/06/14/3 - | |
References | () http://www.osvdb.org/82728 - | |
References | () http://www.securityfocus.com/bid/53838 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/76150 - |
Information
Published : 2012-06-27 00:55
Updated : 2024-11-21 01:39
NVD link : CVE-2012-2721
Mitre link : CVE-2012-2721
CVE.ORG link : CVE-2012-2721
JSON object : View
Products Affected
moshe_weitzman
- organic_groups
drupal
- drupal
CWE
CWE-264
Permissions, Privileges, and Access Controls