CVE-2016-3169: High severity debian linux vulnerability
Saving user accounts can sometimes grant the user all roles
Other sources
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the usersave function with an explicit category and loads all roles into the array.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3169?
CVE-2016-3169 has a moderate severity level as it can allow unauthorized privilege escalation in Drupal.
How do I fix CVE-2016-3169?
To fix CVE-2016-3169, update your Drupal installation to version 6.38 or 7.43 or later.
What affected versions are vulnerable to CVE-2016-3169?
CVE-2016-3169 affects Drupal 6.x prior to 6.38 and Drupal 7.x prior to 7.43.
What types of attacks can CVE-2016-3169 enable?
CVE-2016-3169 can enable attackers to gain unauthorized privileges by exploiting vulnerabilities in contributed or custom code.
Is my Drupal site at risk due to CVE-2016-3169?
If you are using Drupal versions 6.x below 6.38 or 7.x below 7.43, your site is at risk and should be updated immediately.