Lucene search

K
cve[email protected]CVE-2009-3442
HistorySep 28, 2009 - 10:30 p.m.

CVE-2009-3442

2009-09-2822:30:00
CWE-264
web.nvd.nist.gov
22
cve-2009-3442
meta tags module
drupal
permissions
sensitive information disclosure

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.2%

The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows remote attackers to obtain sensitive information via unspecified vectors.

Affected configurations

NVD
Node
drupaldrupal
AND
ariel_barreirometa_tagsMatch5.x-1.0
OR
ariel_barreirometa_tagsMatch5.x-1.1
OR
ariel_barreirometa_tagsMatch5.x-1.2
OR
ariel_barreirometa_tagsMatch5.x-1.3
OR
ariel_barreirometa_tagsMatch5.x-1.4
OR
ariel_barreirometa_tagsMatch5.x-1.x-dev
OR
ariel_barreirometa_tagsMatch6.x-1.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.2%

Related for CVE-2009-3442