Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-2153
HistoryOct 01, 2012 - 12:00 a.m.

CVE-2012-2153

2012-10-0100:00:00
ubuntu.com
ubuntu.com
14

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

60.4%

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list
when using a “contributed node access module,” which allows remote
authenticated users with the “Access the content overview page” permission
to read all published nodes by accessing the admin/content page.

Bugs

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

60.4%