CVE-2015-3231

Drupal 7.x < 7.38 - Authenticated Exposure of Sensitive Information via Render Cache

Title source: llm
STIX 2.1

Description

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

References (5)

Core 5
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161265.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3291
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html
Vendor Advisory x_refsource_confirm
https://www.drupal.org/SA-CORE-2015-002
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75286

Scores

EPSS 0.0045
EPSS Percentile 63.9%

Details

CWE
CWE-200
Status published
Products (35)
debian/debian_linux 7.0
debian/debian_linux 8.0
drupal/drupal 7.0 (16 CPE variants)
drupal/drupal 7.1
drupal/drupal 7.2
drupal/drupal 7.3
drupal/drupal 7.4
drupal/drupal 7.5
drupal/drupal 7.6
drupal/drupal 7.7
... and 25 more
Published Jun 22, 2015
Tracked Since Feb 18, 2026