CVE-2012-2153: Medium severity drupal vulnerability
Published Oct 1, 2012
·Updated
Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.
Affected Software
31 affected componentsFixes available
composer/drupal/drupal>=7.0<7.14
7.14
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.x-dev
Remediation
Patch Available
Event History
Oct 1, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 17, 2022
Advisory Published
04:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-2153?
CVE-2012-2153 is considered a moderate severity vulnerability.
2
How do I fix CVE-2012-2153?
To mitigate CVE-2012-2153, upgrade your Drupal installation to version 7.14 or later.
3
What is the impact of CVE-2012-2153?
CVE-2012-2153 allows authenticated users with certain permissions to view all published nodes, potentially exposing sensitive content.
4
Is CVE-2012-2153 applicable to all versions of Drupal?
CVE-2012-2153 specifically affects Drupal 7.x versions prior to 7.14.
5
Who is affected by CVE-2012-2153?
Remote authenticated users with the 'Access the content overview page' permission can be impacted by CVE-2012-2153.