Lucene search

K
cve[email protected]CVE-2012-2707
HistoryJun 27, 2012 - 12:55 a.m.

CVE-2012-2707

2012-06-2700:55:04
CWE-264
web.nvd.nist.gov
20
cve-2012-2707
hostmaster module
aegir module
drupal
access restrictions
bypass
remote attackers

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7 High

AI Score

Confidence

Low

0.03 Low

EPSS

Percentile

91.0%

The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does not properly exit when users do not have access to package/task nodes, which allows remote attackers to bypass intended access restrictions and edit unauthorized nodes.

Affected configurations

NVD
Node
antoine_beauprehostmasterMatch6.x-1.2
OR
antoine_beauprehostmasterMatch6.x-1.3
OR
antoine_beauprehostmasterMatch6.x-1.4
OR
antoine_beauprehostmasterMatch6.x-1.5
OR
antoine_beauprehostmasterMatch6.x-1.6
OR
antoine_beauprehostmasterMatch6.x-1.7
OR
antoine_beauprehostmasterMatch6.x-1.8
OR
antoine_beauprehostmasterMatch6.x-1.xdev
AND
drupaldrupalMatch-

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7 High

AI Score

Confidence

Low

0.03 Low

EPSS

Percentile

91.0%

Related for CVE-2012-2707