2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-3232" ,
"sourceIdentifier" : "secalert@redhat.com" ,
"published" : "2015-06-22T19:59:00.997" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T02:28:57.583" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de la redirecci\u00f3n abierta en el m\u00f3dulo Field UI en Drupal 7.x anterior a 7.38 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a trav\u00e9s de una URL en el par\u00e1metro destinations."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 4.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "48C33CAB-4633-418C-B162-20A2EC24E8DD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha1:*:*:*:*:*:*" ,
"matchCriteriaId" : "CC3B1750-17AD-4386-B6EE-1AFC9CDFB6C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha2:*:*:*:*:*:*" ,
"matchCriteriaId" : "9E0C1873-22A6-4CE9-853D-2A40BD3D9E62"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha3:*:*:*:*:*:*" ,
"matchCriteriaId" : "9F6DF608-0DA2-455F-AD28-7BE4A7548E48"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha4:*:*:*:*:*:*" ,
"matchCriteriaId" : "7BCC306D-EB5D-4784-B0B1-B4F9370796F7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha5:*:*:*:*:*:*" ,
"matchCriteriaId" : "5639A5F3-CD18-451C-BA5A-3336C42BED83"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha6:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B0A10CA-F59E-48AC-97E9-8476F63BAEDB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:alpha7:*:*:*:*:*:*" ,
"matchCriteriaId" : "07B7917C-5934-4AFF-B3DB-BE9B099B27FB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:beta1:*:*:*:*:*:*" ,
"matchCriteriaId" : "16731B53-3CD1-4B98-947B-7621162D8DB3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:beta2:*:*:*:*:*:*" ,
"matchCriteriaId" : "BD738402-A50E-4AEB-8F42-607F52DE5540"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:beta3:*:*:*:*:*:*" ,
"matchCriteriaId" : "199AC10C-6E65-409B-8658-E26240B27E1B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:dev:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B378BEF-B070-4955-A6B3-8F2ACBA96832"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "19EC9A36-5EDC-4519-802E-BEA69B18800A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "8C281EA7-8AE1-4D5A-B03B-B3BE37740195"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "024CF5B1-1875-4785-ACAF-35ECCC7914A5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.0:rc4:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F446903-51AC-4FA3-BA90-C2EA59BBDB01"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1FE86CC5-956E-4F16-BE7B-2B1CAAEB5C40"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F0AC1B21-D3BE-4B6A-AE40-8B395E81DD50"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E5E8A73-1C02-4900-BC30-83084DC8371C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A92A41E3-BF0F-49BD-9F0F-5FDC11BF2499"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "937C3149-3F34-40D8-964D-FB65EBDF0BC5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "90CD183A-3777-44F9-8CA6-8E802058D099"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "68C0CC63-558B-4750-8293-926BE9EAD42C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA66BCA5-3934-449E-BAD3-D0DFBF4A04BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5030281C-CD4F-4106-A100-332A4C3C2AEB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D408134A-29E8-4D6A-9352-DB7F9CF55FA3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3B08C41E-2357-44D5-A3A7-75389B343B8C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E9F40588-308A-4BA7-AE62-5DCC7D7528EE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E41BD65A-F39B-42C5-8776-CE09345A531D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CBAFBC02-38E9-41F3-8944-6F6AB0A85941"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9069C99D-C935-4272-B7F4-172CFD246835"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "41BE2EAA-CC60-4EFA-9E75-61EDA0EB69B5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "71CABDC4-0E47-4E33-9075-79E0D59D9A92"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.18:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "74A5893C-A855-4C49-A17A-83B6172C0496"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.19:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4048A2C7-9646-42E3-9D4B-DE9CF4AC66C0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2C915139-9B3A-4583-99A9-3447ACEF9E95"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "01BE6A75-15F2-416C-9EBB-6FDD995C7399"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.22:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B0D82630-555A-43CE-986D-2D15DD8A68F2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AB9F1B32-B3C0-47AB-96C1-0AEF7A96744A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.24:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A23E72D9-9301-4CF8-A083-0AEC91F2845E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.25:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "983636D8-084A-40AA-8EEA-39D4D39EA056"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.26:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5FEAA6C1-D2F5-4C7A-AEEA-FEDD52F039B8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.27:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BCAC8831-637A-49B7-9DFD-93965D0944A6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.28:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "247FF6EA-E8E8-4AC9-BC03-6D8929DC60EF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.29:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "73AAA716-1DB3-4D38-A52B-F579EE5627AD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.30:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "18257E82-134E-4B4B-9AA4-997582A6FE05"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.33:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "42224177-DEFC-4A23-9707-0C2A96902FDA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.34:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2C0017C6-C985-4F0C-89C4-198063DAB3FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.35:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EA2A100A-4579-4E32-9ED1-54E6063032CA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.36:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9B41BB85-CED1-4CED-A56E-A58A22AAE4CA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:drupal:drupal:7.37:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "19437699-98F7-40EC-B0F9-502CA8126749"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "16F59A04-14CF-49E2-9973-645477EA09DA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161265.html" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "http://www.debian.org/security/2015/dsa-3291" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "http://www.securityfocus.com/bid/75287" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://www.drupal.org/SA-CORE-2015-002" ,
"source" : "secalert@redhat.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161265.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.debian.org/security/2015/dsa-3291" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/75287" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://www.drupal.org/SA-CORE-2015-002" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
2024-12-08 03:06:42 +00:00
] ,
"evaluatorComment" : "<a href=\"http://cwe.mitre.org/data/definitions/601.html\">CWE-601: URL Redirection to Untrusted Site ('Open Redirect')</a>"
2023-04-24 12:24:31 +02:00
}