Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2014-111
HistoryNov 19, 2014 - 12:00 a.m.

SA-CONTRIB-2014-111 - Protected Pages - Password Protection Bypass

2014-11-1900:00:00
Drupal Security Team
www.drupal.org
10

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.007

Percentile

80.0%

Protected Pages modules allows the administrator to secure any page in your website by password by configuring a add path and the associated password.

The module did not sufficiently protect variations on the protected path.

CVE identifier(s) issued

  • CVE-2014-9024

Versions affected

  • Protected Pages 7.x-2.x versions prior to 7.x-2.2.

Drupal core is not affected. If you do not use the contributed Protected Pages module,
there is nothing you need to do.

Solution

Install the latest version:

Also see the Protected Pages project page.

Reported by

Fixed by

Coordinated by

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.007

Percentile

80.0%

Related for DRUPAL-SA-CONTRIB-2014-111