CVE-2012-5655: Medium severity steven jones context vulnerability
The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5655?
CVE-2012-5655 is considered a moderate severity vulnerability due to improper access controls in the Context module.
How do I fix CVE-2012-5655?
To fix CVE-2012-5655, update the Context module to version 6.x-3.1 or 7.x-3.0-beta6 and later.
Who is affected by CVE-2012-5655?
CVE-2012-5655 affects installations of the Context module prior to the patched versions on Drupal 6.x and 7.x.
What type of vulnerability is CVE-2012-5655?
CVE-2012-5655 is an access control vulnerability that allows unauthorized access to sensitive information.
Can I still use the Context module if I have CVE-2012-5655 installed?
While you can still use the Context module, it is highly recommended to update immediately to mitigate risks associated with CVE-2012-5655.