CVE Vulnerabilities

CVE-2012-4483

Published: Oct 31, 2012 | Modified: Nov 13, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing.

Affected Software

Name Vendor Start Version End Version
Commons Acquia 6.x-2.4 (including) 6.x-2.4 (including)
Commons Acquia 6.x-2.5 (including) 6.x-2.5 (including)
Commons Acquia 6.x-2.6 (including) 6.x-2.6 (including)
Commons Acquia 6.x-2.7 (including) 6.x-2.7 (including)
Commons Acquia 6.x-2.x-dev (including) 6.x-2.x-dev (including)

References