The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
CPE | Name | Operator | Version |
---|---|---|---|
debian_linux | eq | 8.0 | |
debian_linux | eq | 7.0 | |
drupal | eq | 7.0 alpha5 | |
drupal | eq | 7.0 dev | |
drupal | eq | 7.0 alpha7 | |
drupal | eq | 7.16 | |
drupal | eq | 7.21 | |
drupal | eq | 7.0 rc2 | |
drupal | eq | 7.18 | |
drupal | eq | 7.15 |