CVE-2012-4554: Medium severity drupal vulnerability
Published Nov 11, 2012
·Updated
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.
Affected Software
31 affected components
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.14
Drupal Drupal=7.15
Remediation
Patch Available
Patch Available
Event History
Nov 11, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4554?
The severity of CVE-2012-4554 is classified as a critical vulnerability due to its potential for remote file access.
2
How do I fix CVE-2012-4554?
To fix CVE-2012-4554, you should upgrade your Drupal installation to version 7.16 or later.
3
What systems are affected by CVE-2012-4554?
CVE-2012-4554 affects all versions of Drupal 7.x prior to 7.16.
4
What type of vulnerability is CVE-2012-4554?
CVE-2012-4554 is a file disclosure vulnerability that allows remote OpenID servers to read arbitrary files.
5
Is my data at risk if I am using an affected version of Drupal for CVE-2012-4554?
Yes, using an affected version of Drupal for CVE-2012-4554 puts your data at risk of unauthorized access.