CVE-2015-5490
Summary
| CVE | CVE-2015-5490 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-18 17:59:31 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intended filters and obtain access to hidden content via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Views Project | Views | 7.x-3.10 | All | All | All |
| Application | Views Project | Views | 7.x-3.5 | All | All | All |
| Application | Views Project | Views | 7.x-3.6 | All | All | All |
| Application | Views Project | Views | 7.x-3.7 | All | All | All |
| Application | Views Project | Views | 7.x-3.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| _views_fetch_data() prone to inconsistency (Especially with redis / memcache) [#2475669] | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Exploit |
| views 7.x-3.11 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch |
| oss-security - CVE requests for Drupal contributed modules (from SA-CONTRIB-2015-100 to SA-CONTRIB-2015-131) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Views - Critical - Access Bypass - SA-CONTRIB-2015-103 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch, Vendor Advisory |
| Drupal Views Module Access Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Issue by das-peter: Ensure that we do not end up with broken views data cache entries. (cef693bc) · Commits · project / views · GitLab | af854a3a-2127-422b-91ae-364da2661108 | cgit.drupalcode.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.