CVE Vulnerabilities

CVE-2013-7068

Published: Apr 29, 2014 | Modified: Apr 29, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.

Affected Software

Name Vendor Start Version End Version
Organic_groups Organic_groups_project 7.x-2.0 (including) 7.x-2.0 (including)
Organic_groups Organic_groups_project 7.x-2.0-alpha1 (including) 7.x-2.0-alpha1 (including)
Organic_groups Organic_groups_project 7.x-2.0-alpha2 (including) 7.x-2.0-alpha2 (including)
Organic_groups Organic_groups_project 7.x-2.0-alpha3 (including) 7.x-2.0-alpha3 (including)
Organic_groups Organic_groups_project 7.x-2.0-beta1 (including) 7.x-2.0-beta1 (including)
Organic_groups Organic_groups_project 7.x-2.0-beta2 (including) 7.x-2.0-beta2 (including)
Organic_groups Organic_groups_project 7.x-2.0-beta3 (including) 7.x-2.0-beta3 (including)
Organic_groups Organic_groups_project 7.x-2.0-beta4 (including) 7.x-2.0-beta4 (including)
Organic_groups Organic_groups_project 7.x-2.0-rc1 (including) 7.x-2.0-rc1 (including)
Organic_groups Organic_groups_project 7.x-2.0-rc2 (including) 7.x-2.0-rc2 (including)
Organic_groups Organic_groups_project 7.x-2.0-rc3 (including) 7.x-2.0-rc3 (including)
Organic_groups Organic_groups_project 7.x-2.0-rc4 (including) 7.x-2.0-rc4 (including)
Organic_groups Organic_groups_project 7.x-2.1 (including) 7.x-2.1 (including)
Organic_groups Organic_groups_project 7.x-2.2 (including) 7.x-2.2 (including)
Organic_groups Organic_groups_project 7.x-2.x-dev (including) 7.x-2.x-dev (including)
Drupal6 Ubuntu lucid *
Drupal6 Ubuntu precise *
Drupal6 Ubuntu quantal *
Drupal6 Ubuntu raring *
Drupal7 Ubuntu precise *
Drupal7 Ubuntu quantal *
Drupal7 Ubuntu raring *
Drupal7 Ubuntu saucy *
Drupal7 Ubuntu utopic *
Drupal7 Ubuntu vivid *
Drupal7 Ubuntu wily *
Drupal7 Ubuntu yakkety *

References