CVE-2014-1400: Medium severity entity api for drupal vulnerability
The entityaccess API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1400?
CVE-2014-1400 is considered a medium severity vulnerability as it allows remote authenticated users to bypass access restrictions.
How do I fix CVE-2014-1400?
To fix CVE-2014-1400, update the Entity API module to version 7.x-1.3 or later.
Who is affected by CVE-2014-1400?
CVE-2014-1400 affects users of the Entity API module for Drupal versions 7.x-1.0, 7.x-1.1, and 7.x-1.2.
What types of access are affected by CVE-2014-1400?
CVE-2014-1400 allows access to unpublished comments that should not be visible to unauthorized users.
What systems are impacted by CVE-2014-1400?
CVE-2014-1400 impacts systems running Fedora 19 and 20 as well as Drupal installations using the affected versions of the Entity API module.