First published: Mon Feb 15 2016(Updated: )
Saving user accounts can sometimes grant the user all roles
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0<8.0.4 | |
composer/drupal/drupal | >=8.0<8.0.4 | |
composer/drupal/drupal | >=6.0<6.38 | 6.38 |
composer/drupal/drupal | >=7.0<7.43 | 7.43 |
composer/drupal/core | >=7.0<7.43 | 7.43 |
composer/drupal/core | >=6.0<6.38 | 6.38 |
Debian Linux | =7.0 | |
Debian Linux | =8.0 | |
Drupal | =6.0 | |
Drupal | =6.0-beta1 | |
Drupal | =6.0-beta2 | |
Drupal | =6.0-beta3 | |
Drupal | =6.0-beta4 | |
Drupal | =6.0-dev | |
Drupal | =6.0-rc1 | |
Drupal | =6.0-rc2 | |
Drupal | =6.0-rc3 | |
Drupal | =6.0-rc4 | |
Drupal | =6.1 | |
Drupal | =6.2 | |
Drupal | =6.3 | |
Drupal | =6.4 | |
Drupal | =6.5 | |
Drupal | =6.6 | |
Drupal | =6.7 | |
Drupal | =6.8 | |
Drupal | =6.9 | |
Drupal | =6.10 | |
Drupal | =6.11 | |
Drupal | =6.12 | |
Drupal | =6.13 | |
Drupal | =6.14 | |
Drupal | =6.15 | |
Drupal | =6.16 | |
Drupal | =6.17 | |
Drupal | =6.18 | |
Drupal | =6.19 | |
Drupal | =6.20 | |
Drupal | =6.21 | |
Drupal | =6.22 | |
Drupal | =6.23 | |
Drupal | =6.24 | |
Drupal | =6.25 | |
Drupal | =6.26 | |
Drupal | =6.27 | |
Drupal | =6.28 | |
Drupal | =6.29 | |
Drupal | =6.30 | |
Drupal | =6.31 | |
Drupal | =6.32 | |
Drupal | =6.33 | |
Drupal | =6.34 | |
Drupal | =6.35 | |
Drupal | =6.36 | |
Drupal | =6.37 | |
Drupal | =7.0 | |
Drupal | =7.0-alpha1 | |
Drupal | =7.0-alpha2 | |
Drupal | =7.0-alpha3 | |
Drupal | =7.0-alpha4 | |
Drupal | =7.0-alpha5 | |
Drupal | =7.0-alpha6 | |
Drupal | =7.0-alpha7 | |
Drupal | =7.0-beta1 | |
Drupal | =7.0-beta2 | |
Drupal | =7.0-beta3 | |
Drupal | =7.0-dev | |
Drupal | =7.0-rc1 | |
Drupal | =7.0-rc2 | |
Drupal | =7.0-rc3 | |
Drupal | =7.0-rc4 | |
Drupal | =7.1 | |
Drupal | =7.2 | |
Drupal | =7.3 | |
Drupal | =7.4 | |
Drupal | =7.5 | |
Drupal | =7.6 | |
Drupal | =7.7 | |
Drupal | =7.8 | |
Drupal | =7.9 | |
Drupal | =7.10 | |
Drupal | =7.11 | |
Drupal | =7.12 | |
Drupal | =7.13 | |
Drupal | =7.14 | |
Drupal | =7.15 | |
Drupal | =7.16 | |
Drupal | =7.17 | |
Drupal | =7.18 | |
Drupal | =7.19 | |
Drupal | =7.20 | |
Drupal | =7.21 | |
Drupal | =7.22 | |
Drupal | =7.23 | |
Drupal | =7.24 | |
Drupal | =7.25 | |
Drupal | =7.26 | |
Drupal | =7.27 | |
Drupal | =7.28 | |
Drupal | =7.29 | |
Drupal | =7.30 | |
Drupal | =7.31 | |
Drupal | =7.32 | |
Drupal | =7.33 | |
Drupal | =7.34 | |
Drupal | =7.35 | |
Drupal | =7.36 | |
Drupal | =7.37 | |
Drupal | =7.38 | |
Drupal | =7.40 | |
Drupal | =7.41 | |
Drupal | =7.42 | |
Drupal | =7.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3169 has a moderate severity level as it can allow unauthorized privilege escalation in Drupal.
To fix CVE-2016-3169, update your Drupal installation to version 6.38 or 7.43 or later.
CVE-2016-3169 affects Drupal 6.x prior to 6.38 and Drupal 7.x prior to 7.43.
CVE-2016-3169 can enable attackers to gain unauthorized privileges by exploiting vulnerabilities in contributed or custom code.
If you are using Drupal versions 6.x below 6.38 or 7.x below 7.43, your site is at risk and should be updated immediately.