Vulnerability Bulletins

SA-CORE-2011-002 - Drupal core - Access bypass

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2011-002Project: Drupal coreVersion: 7.xDate: 2011-JUNE-29Security risk: Highly criticalExploitable from: RemoteVulnerability: Access bypassDescriptionCVE: CVE-2011-2687Access bypass in node listingsListings showing nodes but not JOINing the node table show all nodes regardless of restrictions imposed by the node_access system. In core, this affects the taxonomy and the forum subsystem.This issue only affects sites using a node access module such as content access or

More info:

https://www.drupal.org/node/1204582