CVE-2013-7067: Medium severity Mike Stefanello Og Features vulnerability
The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows remote attackers to bypass intended access restrictions via a request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/OG Features moduleto a version that resolves this vulnerability.Fixed in 6.x-1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7067?
CVE-2013-7067 has a severity rating that indicates a significant risk to applications using the OG Features module.
How do I fix CVE-2013-7067?
To fix CVE-2013-7067, you should upgrade the OG Features module to version 6.x-1.4 or later.
What does CVE-2013-7067 allow attackers to do?
CVE-2013-7067 allows attackers to bypass access controls and restrictions meant to limit page access.
Which versions of the OG Features module are affected by CVE-2013-7067?
CVE-2013-7067 affects OG Features versions 6.x-1.0 to 6.x-1.3 before the 6.x-1.4 update.
Is CVE-2013-7067 related to Drupal security?
Yes, CVE-2013-7067 is a vulnerability that impacts Drupal sites using the OG Features module.