CVE-2013-4228
Summary
| CVE | CVE-2013-4228 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-18 19:15:00 UTC |
| Updated | 2020-02-26 19:43:00 UTC |
| Description | The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | - | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | alpha1 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | alpha2 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | alpha3 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta1 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta2 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta3 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta4 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc1 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc2 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc3 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc4 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.1 | All | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.2 | All | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | - | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | alpha1 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | alpha2 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | alpha3 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta1 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta2 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta3 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | beta4 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc1 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc2 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc3 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.0 | rc4 | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.1 | All | All | All |
| Application | Organic Groups Project | Organic Groups | 7.x-2.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| og 7.x-2.3 | drupal.org | MISC | drupal.org | Release Notes, Vendor Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| SA-CONTRIB-2013-065 - Organic Groups - Access Bypass | Drupal.org | MISC | drupal.org | Vendor Advisory |
| Drupal Organic Groups Module Multiple Security Vulnerabilities | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - Re: CVE request for Drupal contributed modules | MISC | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.