Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-5020
HistoryJul 22, 2014 - 12:00 a.m.

CVE-2014-5020

2014-07-2200:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

EPSS

0.001

Percentile

44.0%

The File module in Drupal 7.x before 7.29 does not properly check
permissions to view files, which allows remote authenticated users with
certain permissions to bypass intended restrictions and read files by
attaching the file to content with a file field.

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchdrupal7< anyUNKNOWN

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

EPSS

0.001

Percentile

44.0%