← Back

CVE-2012-1635

nvd nist
Published: Aug 28, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

The hook_node_access function in the revisioning module 7.x-1.x before 7.x-1.3 for Drupal checks the permissions of the current user even when it is called to check permissions of other users, which allows remote attackers to bypass intended access restrictions, as demonstrated when using the XML sitemap module to obtain sensitive information about unpublished content.

Affected (21)

1 product
Revisioning
Configuration A
21 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Rik De Boer
Version 7.x-1.0
Version 7.x-1.0 alpha1
Version 7.x-1.0 alpha2
Version 7.x-1.0 alpha3
Version 7.x-1.0 alpha4
Version 7.x-1.0 alpha5
Version 7.x-1.0 beta10
Version 7.x-1.0 beta11
Version 7.x-1.0 beta1
Version 7.x-1.0 beta2
Version 7.x-1.0 beta3
Version 7.x-1.0 beta4
Version 7.x-1.0 beta5
Version 7.x-1.0 beta6
Version 7.x-1.0 beta7
Version 7.x-1.0 beta8
Version 7.x-1.0 beta9
Version 7.x-1.1
Version 7.x-1.2
Version 7.x-1.x
Version 7.x-1.x dev
Running on/withPlatform Versions
Drupal
Drupal
All versions

Related CWEs

References (6)

Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.