René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

128 lines
4.3 KiB
JSON

{
"id": "CVE-2015-7226",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-09-17T16:59:05.087",
"lastModified": "2016-11-28T19:42:43.667",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler."
},
{
"lang": "es",
"value": "Vulnerabilidad en el m\u00f3dulo Administration Views 7.x-1.x en versiones anteriores a 7.x-1.5 para Drupal, comprueba los permisos de acceso bas\u00e1ndose en la ruta del router desde view en lugar de la propiedad display, lo que permite a atacantes remotos obtener informaci\u00f3n sensible a trav\u00e9s de vectores relacionados con el manejo de accesos."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.0:*:*:*:*:drupal:*:*",
"matchCriteriaId": "12E31109-601D-4962-998C-0AE06A4A2587"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.0:rc1:*:*:*:drupal:*:*",
"matchCriteriaId": "D2375B7C-3AEE-44D5-B851-337259C60862"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.1:*:*:*:*:drupal:*:*",
"matchCriteriaId": "0BB101A0-9F5E-4ACF-85F4-2FB747811469"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.2:*:*:*:*:drupal:*:*",
"matchCriteriaId": "BE803C20-D397-445C-8932-E659ABAA1F8D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.3:*:*:*:*:drupal:*:*",
"matchCriteriaId": "4CD5FEA7-7DF5-490B-8BD4-66AE53D6C22E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.4:*:*:*:*:drupal:*:*",
"matchCriteriaId": "2842E1D2-DC11-4D59-85AA-BE0A7B631B00"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:administration_views_project:administration_views:7.x-1.x:dev:*:*:*:drupal:*:*",
"matchCriteriaId": "C9613673-C043-46CA-BF5E-B37533834693"
}
]
}
]
}
],
"references": [
{
"url": "http://cgit.drupalcode.org/admin_views/commit/?id=44098bb",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/75697",
"source": "cve@mitre.org"
},
{
"url": "https://www.drupal.org/node/2529366",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "https://www.drupal.org/node/2529378",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}