CVE-2014-1399: Medium severity entity api for drupal vulnerability
Published Apr 10, 2018
·Updated
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
Affected Software
5 affected components
Entity Api Project Entity Api Drupal=7.x-1.0
Entity Api Project Entity Api Drupal=7.x-1.1
Entity Api Project Entity Api Drupal=7.x-1.2
Fedoraproject Fedora=19
Fedoraproject Fedora=20
Remediation
Patch Available
Event History
Apr 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1399?
CVE-2014-1399 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-1399?
To fix CVE-2014-1399, upgrade the Entity API module to version 7.x-1.3 or later.
3
Who is affected by CVE-2014-1399?
CVE-2014-1399 affects Drupal sites using the Entity API module versions 7.x-1.0 to 7.x-1.2.
4
What kind of access can be bypassed due to CVE-2014-1399?
CVE-2014-1399 allows remote authenticated users to bypass access restrictions on referenced entities.
5
Is CVE-2014-1399 a coding vulnerability?
Yes, CVE-2014-1399 is a coding vulnerability within the Entity wrapper access API of the Entity API module.