4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
0.001 Low
EPSS
Percentile
50.0%
The Memcache project provides an alternative cache backend which works with memcached program to speed up high traffic sites.
The memcache backend caches the current $user object a little too aggressively, which can lead to a role change not being recognized until the user logs in again.
The memcache_admin module does not sanitize some of the user supplied data before displaying it, leading to a Cross Site Scripting (XSS) vulnerability which can be used by a malicious user to gain full administrative access.
Drupal core is not affected. If you do not use the contributed Memcache backend there is nothing you need to do.
Install the latest version:
See also the Memcache project page.