CVE-2012-5655: Medium severity steven jones context vulnerability

Published Jan 3, 2013
·
Updated

The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request.

Affected Software

24 affected components
Steven Jones Context=6.x-3.0
Steven Jones Context=6.x-3.0-alpha1
Steven Jones Context=6.x-3.0-alpha2
Steven Jones Context=6.x-3.0-beta1
Steven Jones Context=6.x-3.0-beta2
Steven Jones Context=6.x-3.0-beta3
Steven Jones Context=6.x-3.0-beta4
Steven Jones Context=6.x-3.0-beta5
Steven Jones Context=6.x-3.0-beta6
Steven Jones Context=6.x-3.0-beta7
Steven Jones Context=6.x-3.0-beta8
Steven Jones Context=6.x-3.0-rc1
Steven Jones Context=6.x-3.0-rc2
Steven Jones Context=6.x-3.x-dev
Steven Jones Context=7.x-3.0-alpha1
Steven Jones Context=7.x-3.0-alpha2
Steven Jones Context=7.x-3.0-alpha3
Steven Jones Context=7.x-3.0-beta1
Steven Jones Context=7.x-3.0-beta2
Steven Jones Context=7.x-3.0-beta3
Steven Jones Context=7.x-3.0-beta4
Steven Jones Context=7.x-3.0-beta5
Steven Jones Context=7.x-3.x-dev
Drupal Drupal

Event History

Jan 3, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2012-5655?

CVE-2012-5655 is considered a moderate severity vulnerability due to improper access controls in the Context module.

2

How do I fix CVE-2012-5655?

To fix CVE-2012-5655, update the Context module to version 6.x-3.1 or 7.x-3.0-beta6 and later.

3

Who is affected by CVE-2012-5655?

CVE-2012-5655 affects installations of the Context module prior to the patched versions on Drupal 6.x and 7.x.

4

What type of vulnerability is CVE-2012-5655?

CVE-2012-5655 is an access control vulnerability that allows unauthorized access to sensitive information.

5

Can I still use the Context module if I have CVE-2012-5655 installed?

While you can still use the Context module, it is highly recommended to update immediately to mitigate risks associated with CVE-2012-5655.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203