CVE-2008-3094: Infoleak
Published Jul 9, 2008
·Updated
The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via unspecified vectors.
Affected Software
11 affected components
Organic Groups Project Organic Groups Drupal=6.x-1.x-dev
Organic Groups Project Organic Groups Drupal=6.x-1.0-beta
Organic Groups Project Organic Groups Drupal=6.x-1.0-alpha
Organic Groups Project Organic Groups Drupal=5.x-5.x-7.2
Organic Groups Project Organic Groups Drupal=5.x-7.1
Organic Groups Project Organic Groups Drupal=5.x-7.0-rc5
Organic Groups Project Organic Groups Drupal=5.x-7.0-rc4
Organic Groups Project Organic Groups Drupal=5.x-7.0-rc3
Organic Groups Project Organic Groups Drupal=5.x-7.0-rc2
Organic Groups Project Organic Groups Drupal=5.x-7.0-rc1
Organic Groups Project Organic Groups Drupal=5.x-7.0
Remediation
Patch Available
Event History
Jul 9, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3094?
CVE-2008-3094 has a moderate severity level due to the potential exposure of sensitive information.
2
How do I fix CVE-2008-3094?
To mitigate CVE-2008-3094, upgrade the Organic Groups module to the latest version that addresses this vulnerability.
3
What kind of information can be exposed by CVE-2008-3094?
CVE-2008-3094 allows attackers to obtain sensitive information, specifically private group names within the application.
4
Which versions are affected by CVE-2008-3094?
CVE-2008-3094 impacts Organic Groups module versions prior to 5.x-7.3 and 6.x-1.0-RC1.
5
Is CVE-2008-3094 a remote attack vulnerability?
Yes, CVE-2008-3094 can be exploited by remote attackers, allowing them to access restricted information.