Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2013-086
HistoryOct 30, 2013 - 12:00 a.m.

SA-CONTRIB-2013-086 - Monster Menus - Access bypass

2013-10-3000:00:00
Drupal Security Team
www.drupal.org
4

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.967 High

EPSS

Percentile

99.7%

Monster Menus includes the ability to protect the visibility of comments for each node based on hierarchical permissions. However, a carefully-crafted URL could be used to bypass these permissions, allowing an anonymous user to view the comments associated with certain nodes.

In order for this flaw to be relevant and exploited, the node itself must be readable by the attacker. Furthermore, the “Who can read comments” setting for the node must be something other than “Everyone”.

CVE identifier(s) issued

  • CVE-2013-4504

Versions affected

  • monster_menus 7.x-1.x versions prior to 7.x-1.15.

Drupal core is not affected. If you do not use the contributed Monster Menus module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the monster_menus module for Drupal 7.x, upgrade to monster_menus 7.x-1.15

Also see the Monster Menus project page.

Reported by

Fixed by

Coordinated by

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2013-086