MEDIUM · 4.3

CVE-2014-5179

The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain se...

Vulnerability Description

The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain sensitive information via a crafted link.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Freelinking For Case Tracker ProjectFreelinking For Case Tracker-
Freelinking ProjectFreelinking-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-5179?

CVE-2014-5179 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain se...

How severe is CVE-2014-5179?

CVE-2014-5179 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5179?

Check the references section above for vendor advisories and patch information. Affected products include: Freelinking For Case Tracker Project Freelinking For Case Tracker, Freelinking Project Freelinking.