CVE-2013-7068: Medium severity Organic Groups Project Organic Groups Drupal vulnerability
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Organic Groups (OG) module 7.x-2.x (Drupal)to a version that resolves this vulnerability.Fixed in 7.x-2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7068?
CVE-2013-7068 has a moderate severity level allowing unauthorized access to nodes.
How do I fix CVE-2013-7068?
To mitigate CVE-2013-7068, you should upgrade the Organic Groups module to version 7.x-2.3 or higher.
Who is affected by CVE-2013-7068?
CVE-2013-7068 affects users of the Organic Groups module versions 7.x-2.0 to 7.x-2.2 for Drupal.
What type of attack does CVE-2013-7068 enable?
CVE-2013-7068 enables remote authenticated users to bypass group restrictions on certain nodes.
What are the consequences of not addressing CVE-2013-7068?
Failing to address CVE-2013-7068 may lead to unauthorized access and potential exposure of sensitive content within user groups.