First published: Mon Jun 22 2015(Updated: )
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | =7.0 | |
Drupal | =7.0-alpha1 | |
Drupal | =7.0-alpha2 | |
Drupal | =7.0-alpha3 | |
Drupal | =7.0-alpha4 | |
Drupal | =7.0-alpha5 | |
Drupal | =7.0-alpha6 | |
Drupal | =7.0-alpha7 | |
Drupal | =7.0-beta1 | |
Drupal | =7.0-beta2 | |
Drupal | =7.0-beta3 | |
Drupal | =7.0-dev | |
Drupal | =7.0-rc1 | |
Drupal | =7.0-rc2 | |
Drupal | =7.0-rc3 | |
Drupal | =7.0-rc4 | |
Drupal | =7.1 | |
Drupal | =7.2 | |
Drupal | =7.3 | |
Drupal | =7.4 | |
Drupal | =7.5 | |
Drupal | =7.6 | |
Drupal | =7.7 | |
Drupal | =7.8 | |
Drupal | =7.9 | |
Drupal | =7.10 | |
Drupal | =7.11 | |
Drupal | =7.12 | |
Drupal | =7.13 | |
Drupal | =7.14 | |
Drupal | =7.15 | |
Drupal | =7.16 | |
Drupal | =7.17 | |
Drupal | =7.18 | |
Drupal | =7.19 | |
Drupal | =7.20 | |
Drupal | =7.21 | |
Drupal | =7.22 | |
Drupal | =7.23 | |
Drupal | =7.24 | |
Drupal | =7.25 | |
Drupal | =7.26 | |
Drupal | =7.27 | |
Drupal | =7.28 | |
Drupal | =7.29 | |
Drupal | =7.30 | |
Drupal | =7.33 | |
Drupal | =7.34 | |
Drupal | =7.35 | |
Drupal | =7.36 | |
Drupal | =7.37 | |
Debian Linux | =7.0 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-3231 is classified as moderate, as it allows remote authenticated users to access private content.
To fix CVE-2015-3231, upgrade to Drupal 7.38 or later, where this vulnerability is patched.
CVE-2015-3231 affects all Drupal 7.x versions prior to 7.38.
CVE-2015-3231 allows remote authenticated users to view private content, which could lead to unauthorized access.
Temporarily, you can restrict access to user roles that do not require viewing private content until you can upgrade.