CVE-2012-4483
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing.
La función commons_discussion_views_default_views en modules/features/modules commons_discussion/commons_discussion.views_default.inc en el módulo Drupal Commons v6.x-2.x antes de v6.x-2.8 para Drupal no aplica correctamente las restricciones de acceso del nodo, lo que podría permitir a atacantes remotos obtener información sensible a través de la lista de comentarios recientes.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-08-21 CVE Reserved
- 2012-10-31 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://drupal.org/node/1679820 | X_refsource_misc | |
http://www.openwall.com/lists/oss-security/2012/10/04/6 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/10/07/1 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/1679908 | 2012-11-13 | |
http://drupalcode.org/project/commons.git/commitdiff/8ef688b | 2012-11-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Acquia Search vendor "Acquia" | Commons Search vendor "Acquia" for product "Commons" | 6.x-2.4 Search vendor "Acquia" for product "Commons" and version "6.x-2.4" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Acquia Search vendor "Acquia" | Commons Search vendor "Acquia" for product "Commons" | 6.x-2.5 Search vendor "Acquia" for product "Commons" and version "6.x-2.5" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Acquia Search vendor "Acquia" | Commons Search vendor "Acquia" for product "Commons" | 6.x-2.6 Search vendor "Acquia" for product "Commons" and version "6.x-2.6" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Acquia Search vendor "Acquia" | Commons Search vendor "Acquia" for product "Commons" | 6.x-2.7 Search vendor "Acquia" for product "Commons" and version "6.x-2.7" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Acquia Search vendor "Acquia" | Commons Search vendor "Acquia" for product "Commons" | 6.x-2.x Search vendor "Acquia" for product "Commons" and version "6.x-2.x" | dev |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|