Vulnerability Description
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | 7.0 |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633385
- http://drupal.org/node/1204582PatchVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062714.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062722.html
- http://secunia.com/advisories/45081Vendor Advisory
- http://secunia.com/advisories/45291Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/07/11/2
- http://www.openwall.com/lists/oss-security/2011/07/12/16
- http://www.securityfocus.com/bid/48505
- https://bugzilla.redhat.com/show_bug.cgi?id=717874
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633385
- http://drupal.org/node/1204582PatchVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062714.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062722.html
- http://secunia.com/advisories/45081Vendor Advisory
FAQ
What is CVE-2011-2687?
CVE-2011-2687 is a vulnerability with a CVSS score of 7.5 (HIGH). Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
How severe is CVE-2011-2687?
CVE-2011-2687 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2687?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal.