CVE-2012-2721
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly…
Does this matter?
Lower severity and a low EPSS score (2.60%). Track it; it rarely justifies an emergency change on its own.
Description
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.60% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- moshe weitzman/organic groups
- Source
- secalert@redhat.com
References
- http://drupal.org/node/1619736Patch
- http://drupal.org/node/1619810Patch, Vendor Advisory
- http://drupalcode.org/project/og.git/commitdiff/1485708Exploit, Patch
- http://secunia.com/advisories/49397Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/06/14/3
- http://www.osvdb.org/82728
- http://www.securityfocus.com/bid/53838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76150
- http://drupal.org/node/1619736Patch
- http://drupal.org/node/1619810Patch, Vendor Advisory
- http://drupalcode.org/project/og.git/commitdiff/1485708Exploit, Patch
- http://secunia.com/advisories/49397Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/06/14/3
- http://www.osvdb.org/82728
- http://www.securityfocus.com/bid/53838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76150
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.