Lucene search

K
osvGoogleOSV:DSA-3291-1
HistoryJun 18, 2015 - 12:00 a.m.

drupal7 - security update

2015-06-1800:00:00
Google
osv.dev
9

0.005 Low

EPSS

Percentile

76.9%

Several vulnerabilities were found in drupal7, a content management
platform used to power websites.

  • CVE-2015-3231
    Incorrect cache handling made private content viewed by user 1
    exposed to other, non-privileged users.
  • CVE-2015-3232
    A flaw in the Field UI module made it possible for attackers to
    redirect users to malicious sites.
  • CVE-2015-3233
    Due to insufficient URL validation, the Overlay module could be
    used to redirect users to malicious sites.
  • CVE-2015-3234
    The OpenID module allowed an attacker to log in as other users,
    including administrators.

For the oldstable distribution (wheezy), these problems have been fixed
in version 7.14-2+deb7u10.

For the stable distribution (jessie), these problems have been fixed in
version 7.32-1+deb8u4.

For the unstable distribution (sid), these problems have been fixed in
version 7.38.1.

We recommend that you upgrade your drupal7 packages.