CVE-2012-5544: Infoleak
Published Dec 3, 2012
·Updated
The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.
Affected Software
6 affected components
Thinkshout Mandrill=7.x-1.0
Thinkshout Mandrill=7.x-1.0-alpha1
Thinkshout Mandrill=7.x-1.0-beta1
Thinkshout Mandrill=7.x-1.1
Thinkshout Mandrill=7.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Dec 3, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5544?
CVE-2012-5544 has a medium severity rating as it allows unauthorized access to sensitive password reset links.
2
How do I fix CVE-2012-5544?
To fix CVE-2012-5544, update the Mandrill module to version 7.x-1.2 or later.
3
Who is affected by CVE-2012-5544?
CVE-2012-5544 affects remote authenticated users of the Mandrill module versions prior to 7.x-1.2.
4
What components of the Mandrill module are vulnerable in CVE-2012-5544?
The vulnerable components in CVE-2012-5544 are the Mandrill dashboard logs that leak password reset links.
5
When was CVE-2012-5544 disclosed?
CVE-2012-5544 was disclosed in November 2012.