Information disclosure in Drupal - CVE-2016-9449

 

Information disclosure in Drupal - CVE-2016-9449

Published: November 25, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40008
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9449
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.


Affected software

Drupal
Arch Linux
Fedora
drupal7

How to mitigate CVE-2016-9449

Install update from vendor's website.

drupal7 - addressed in versions 7.52-1.el5, 7.52-1.el6, 7.52-1.el7, 7.52-1.fc23, 7.52-1.fc24, 7.52-1.fc25

External References

Related Security Bulletins