VulnerabilityModified
CVE-2012-1591
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
MEDIUM 5.0EPSS 2.40%
Does this matter?
Lower severity and a low EPSS score (2.40%). Track it; it rarely justifies an emergency change on its own.
Description
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.40% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- drupal/drupal
- Source
- secalert@redhat.com
References
- http://drupal.org/drupal-7.14Patch
- http://drupal.org/node/1507988
- http://drupal.org/node/1557938Vendor Advisory
- http://drupalcode.org/project/drupal.git/commit/3bf6761ff7537dc68e22ea73f155134f3cfd41a8
- http://secunia.com/advisories/49012
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:074
- http://www.securityfocus.com/bid/53359
- http://drupal.org/drupal-7.14Patch
- http://drupal.org/node/1507988
- http://drupal.org/node/1557938Vendor Advisory
- http://drupalcode.org/project/drupal.git/commit/3bf6761ff7537dc68e22ea73f155134f3cfd41a8
- http://secunia.com/advisories/49012
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:074
- http://www.securityfocus.com/bid/53359
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.