CVE-2013-4498: Low severity Florian Weber Spaces vulnerability
The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4498?
CVE-2013-4498 has a moderate severity rating due to the potential for unauthorized access to orphaned content by remote authenticated users.
How do I fix CVE-2013-4498?
To fix CVE-2013-4498, upgrade to Spaces module version 6.x-3.7 or later.
What types of users are affected by CVE-2013-4498?
Remote authenticated users with the 'access content' permission are affected by CVE-2013-4498.
What is the nature of the issue described in CVE-2013-4498?
CVE-2013-4498 describes a failure to properly delete organic group spaces content when moving to a new group, leading to orphaned content.
Which versions of the Spaces module are vulnerable to CVE-2013-4498?
The vulnerable versions are Spaces module 6.x-3.x before 6.x-3.7, including specific alpha, beta, and release versions up to 6.x-3.6.