Lucene search

K
cveMitreCVE-2015-5490
HistoryAug 18, 2015 - 5:59 p.m.

CVE-2015-5490

2015-08-1817:59:31
CWE-200
mitre
web.nvd.nist.gov
20
cve-2015-5490
drupal
views module
cache
access bypass
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.008

Percentile

81.7%

The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intended filters and obtain access to hidden content via unspecified vectors.

Affected configurations

Nvd
Node
views_projectviewsMatch7.x-3.5drupal
OR
views_projectviewsMatch7.x-3.6drupal
OR
views_projectviewsMatch7.x-3.7drupal
OR
views_projectviewsMatch7.x-3.8drupal
OR
views_projectviewsMatch7.x-3.10drupal
VendorProductVersionCPE
views_projectviews7.x-3.5cpe:2.3:a:views_project:views:7.x-3.5:*:*:*:*:drupal:*:*
views_projectviews7.x-3.6cpe:2.3:a:views_project:views:7.x-3.6:*:*:*:*:drupal:*:*
views_projectviews7.x-3.7cpe:2.3:a:views_project:views:7.x-3.7:*:*:*:*:drupal:*:*
views_projectviews7.x-3.8cpe:2.3:a:views_project:views:7.x-3.8:*:*:*:*:drupal:*:*
views_projectviews7.x-3.10cpe:2.3:a:views_project:views:7.x-3.10:*:*:*:*:drupal:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.008

Percentile

81.7%

Related for CVE-2015-5490