Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2013-054
HistoryJun 26, 2013 - 12:00 a.m.

SA-CONTRIB-2013-054 - Fast Permissions Administration - Access Bypass

2013-06-2600:00:00
Drupal Security Team
www.drupal.org
2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

The Fast Permissions Administration module enables you to use inline filters on the permissions page, as well as loading the permissions form through a modal dialog.

The module doesn’t sufficiently check user access for the modal content callback, allowing unauthorized access to the permissions edit form.

CVE identifier(s) issued

  • CVE-2013-2247

Versions affected

  • Fast Permissions Administration 6.x-2.x versions prior to 6.x-2.5.
  • Fast Permissions Administration 7.x-2.x versions prior to 7.x-2.3.

Drupal core is not affected. If you do not use the contributed Fast Permissions Administration module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Fast Permissions Administration project page.

Reported by

Fixed by

Coordinated by

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2013-054