CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
99.7%
The Drupal Commons distribution is a tool for building social, group-based collaboration communities. The Commons Groups module is used by the distribution to provide specific Organic Groups customizations.
Versions 3.0 and earlier of the Commons Groups module is vulnerable to an access bypass and privilege escalation vulnerability that allows anonymous users to post content into groups.
Drupal core is not affected. If you do not use the contributed Commons Groups module, there is nothing you need to do.
Install the latest version:
Also see the Commons Groups project page.
Commons project maintainers:
Commons project maintainers:
drupal.org/contact
drupal.org/node/1954762
drupal.org/node/1954948
drupal.org/project/commons_groups
drupal.org/security-team
drupal.org/security-team/risk-levels
drupal.org/security/secure-configuration
drupal.org/user/1014606
drupal.org/user/36762
drupal.org/user/45640
drupal.org/user/69959/
drupal.org/user/91990
drupal.org/writing-secure-code