First published: Tue Feb 18 2020(Updated: )
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Organic Groups Project Organic Groups | =7.x-2.0 | |
Organic Groups Project Organic Groups | =7.x-2.0-alpha1 | |
Organic Groups Project Organic Groups | =7.x-2.0-alpha2 | |
Organic Groups Project Organic Groups | =7.x-2.0-alpha3 | |
Organic Groups Project Organic Groups | =7.x-2.0-beta1 | |
Organic Groups Project Organic Groups | =7.x-2.0-beta2 | |
Organic Groups Project Organic Groups | =7.x-2.0-beta3 | |
Organic Groups Project Organic Groups | =7.x-2.0-beta4 | |
Organic Groups Project Organic Groups | =7.x-2.0-rc1 | |
Organic Groups Project Organic Groups | =7.x-2.0-rc2 | |
Organic Groups Project Organic Groups | =7.x-2.0-rc3 | |
Organic Groups Project Organic Groups | =7.x-2.0-rc4 | |
Organic Groups Project Organic Groups | =7.x-2.1 | |
Organic Groups Project Organic Groups | =7.x-2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4228 has a moderate severity rating due to its potential to allow unauthorized access to private group content.
To fix CVE-2013-4228, upgrade the Organic Groups module to version 7.x-2.3 or later.
CVE-2013-4228 affects all versions of the Organic Groups module from 7.x-2.0 to 7.x-2.2.
Yes, CVE-2013-4228 can be exploited remotely by authenticated users.
CVE-2013-4228 allows users to guess node IDs and gain access to content in arbitrary private groups.