Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2013-045
HistoryApr 17, 2013 - 12:00 a.m.

SA-CONTRIB-2013-045 - Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) - Access bypass

2013-04-1700:00:00
Drupal Security Team
www.drupal.org
4

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.967 High

EPSS

Percentile

99.7%

Autocomplete Widgets module adds autocomplete widgets for Text and Number fields.

The autocomplete callback implemented by this module does not honor node permissions to access existing fields, allowing users to see field values even though they are not authorized to access that information.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create or edit content.

CVE identifier(s) issued

  • CVE-2013-1973

Versions affected

  • Autocomplete Widgets 6.x-1.x versions prior to 6.x-1.4.
  • Autocomplete Widgets 7.x-1.x versions prior to 7.x-1.0-rc1.

Drupal core is not affected. If you do not use the contributed Autocomplete Widgets for Text and Number Fields module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Autocomplete Widgets for Text and Number Fields project page.

Reported by

Fixed by

Coordinated by

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2013-045