CVE-2013-1908: Medium severity acquia commons vulnerability
Published Jul 16, 2013
·Updated
The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.
Affected Software
5 affected components
Acquia Commons<=7.x-3.0
Acquia Commons=7.x-3.x-dev
Commons Wikis Project Commons Wikis<=7.x-3.0
Commons Wikis Project Commons Wikis=7.x-3.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jul 16, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1908?
CVE-2013-1908 is considered a moderate severity vulnerability due to improper access restrictions.
2
How do I fix CVE-2013-1908?
To fix CVE-2013-1908, upgrade to Commons module version 7.x-3.1 or higher.
3
What types of attacks does CVE-2013-1908 allow?
CVE-2013-1908 allows remote attackers to post arbitrary content to groups.
4
Which versions of Commons are affected by CVE-2013-1908?
Versions before Commons 7.x-3.1 are affected by CVE-2013-1908.
5
Is Drupal affected by CVE-2013-1908?
Drupal itself is not directly affected, but the Commons module used with Drupal is vulnerable.