CVE-2013-4226: Medium severity drupal authenticated user page caching vulnerability
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-4226?
CVE-2013-4226 is a vulnerability in the Authenticated User Page Caching (Authcache) module for Drupal before version 7.x-1.5.
What is the severity of CVE-2013-4226?
CVE-2013-4226 has a severity rating of 6.5, which is considered medium.
How does CVE-2013-4226 affect Drupal?
CVE-2013-4226 allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
How can I fix CVE-2013-4226?
To fix CVE-2013-4226, upgrade to version 7.x-1.5 or later of the Authenticated User Page Caching (Authcache) module for Drupal.
Where can I find more information about CVE-2013-4226?
More information about CVE-2013-4226 can be found at the following references: [Link 1](http://www.openwall.com/lists/oss-security/2013/08/10/1), [Link 2](https://drupal.org/node/2058165), [Link 3](https://drupal.org/node/2059589).