CVE-2014-1399
MEDIUMEntity API 7.x-1.x < 7.x-1.3 - Authenticated Access Control Bypass
Title source: llmDescription
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/64729
Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126811.html
Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126816.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90216
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/09/3
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1050802
Patch, Vendor Advisory x_refsource_misc
https://www.drupal.org/node/2169595
Scores
CVSS v3
6.5
EPSS
0.0142
EPSS Percentile
69.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-284
Status
published
Products (5)
entity_api_project/entity_api
7.x-1.0
entity_api_project/entity_api
7.x-1.1
entity_api_project/entity_api
7.x-1.2
fedoraproject/fedora
19
fedoraproject/fedora
20
Published
Apr 10, 2018
Tracked Since
Feb 18, 2026