CVE-2015-4345: Infoleak
The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4345?
CVE-2015-4345 has been classified as a moderate severity vulnerability that can lead to the exposure of sensitive information.
How do I fix CVE-2015-4345?
To fix CVE-2015-4345, update the Restful Web Services module to version 7.x-1.5 or 7.x-2.3 or later.
What does CVE-2015-4345 affect?
CVE-2015-4345 affects versions 7.x-1.0 to 7.x-1.4 and 7.x-2.0 to 7.x-2.2 of the Restful Web Services module for Drupal.
Can CVE-2015-4345 be exploited remotely?
Yes, CVE-2015-4345 allows remote attackers to exploit the vulnerability to obtain sensitive information.
What are the potential consequences of CVE-2015-4345?
The potential consequences of CVE-2015-4345 include unauthorized access to sensitive data through cached pages.