Access bypass in Drupal - CVE-2012-5652

 

Access bypass in Drupal - CVE-2012-5652

Published: September 15, 2016 / Updated: September 15, 2016


Vulnerability identifier: #VU464
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5652
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to look the uploaded files over.
The weakness exists due to access control error and results in showing of uploaded files in RSS feeds and search results. The vulnerability increases possibility to view the information by users not allowed to read it before.
Successful exploitation of the weakness allows malicious users to obtain uploaded files.

Affected software

Drupal
Fedora
drupal6
drupal7

How to mitigate CVE-2012-5652


drupal6 - addressed in versions 6.27-1.el5, 6.27-1.el6
drupal7 - addressed in versions 7.18-1.el5, 7.18-1.el6

External References

Related Security Bulletins