{"api_version":"1","generated_at":"2026-07-23T07:55:49+00:00","cve":"CVE-2012-5586","urls":{"html":"https://cve.report/CVE-2012-5586","api":"https://cve.report/api/cve/CVE-2012-5586.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5586","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5586"},"summary":{"title":"CVE-2012-5586","description":"The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the \"access user profiles\" permission to access arbitrary users' emails via vectors related to the \"user index method\" and \"the path to the user resource.\"","state":"PUBLISHED","assigner":"redhat","published_at":"2012-12-26 17:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:N/AC:H/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://drupal.org/node/1842022","name":"http://drupal.org/node/1842022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"services 7.x-3.3 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/11/29/2","name":"http://www.openwall.com/lists/oss-security/2012/11/29/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE request for Drupal contributed modules","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/56723","name":"http://www.securityfocus.com/bid/56723","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Services Module CVE-2012-5586 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://drupal.org/node/1853200","name":"http://drupal.org/node/1853200","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SA-CONTRIB-2012-168 - Services - Information Disclosure | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/1842026","name":"http://drupal.org/node/1842026","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"services 6.x-3.3 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5586","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5586","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5586","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"alpha1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"rc3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"rc4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"unstable1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"unstable2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.0","cpe7":"unstable3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"6.x-3.x","cpe7":"dev","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"rc3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"rc4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"rc5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.0","cpe7":"rc6","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"marc_ingram","cpe5":"services","cpe6":"7.x-3.x","cpe7":"dev","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:14:15.921Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/1842026"},{"name":"56723","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/56723"},{"name":"[oss-security] 20121128 Re: CVE request for Drupal contributed modules","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/11/29/2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://drupal.org/node/1853200"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/1842022"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the \"access user profiles\" permission to access arbitrary users' emails via vectors related to the \"user index method\" and \"the path to the user resource.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-02-26T10:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/1842026"},{"name":"56723","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/56723"},{"name":"[oss-security] 20121128 Re: CVE request for Drupal contributed modules","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/11/29/2"},{"tags":["x_refsource_MISC"],"url":"http://drupal.org/node/1853200"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/1842022"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2012-5586","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the \"access user profiles\" permission to access arbitrary users' emails via vectors related to the \"user index method\" and \"the path to the user resource.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://drupal.org/node/1842026","refsource":"CONFIRM","url":"http://drupal.org/node/1842026"},{"name":"56723","refsource":"BID","url":"http://www.securityfocus.com/bid/56723"},{"name":"[oss-security] 20121128 Re: CVE request for Drupal contributed modules","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/11/29/2"},{"name":"http://drupal.org/node/1853200","refsource":"MISC","url":"http://drupal.org/node/1853200"},{"name":"http://drupal.org/node/1842022","refsource":"CONFIRM","url":"http://drupal.org/node/1842022"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-5586","datePublished":"2012-12-26T17:00:00.000Z","dateReserved":"2012-10-24T00:00:00.000Z","dateUpdated":"2024-08-06T21:14:15.921Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-12-26 17:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:N/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:*:*:*:*:*:*:*","matchCriteriaId":"8709726B-3CC9-4149-8FFA-57ACB47E1232"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:alpha1:*:*:*:*:*:*","matchCriteriaId":"7F8D4108-3D6C-4443-A27E-A0853A5398B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:beta1:*:*:*:*:*:*","matchCriteriaId":"E59520DC-4B1D-4C78-846F-4A7E092C0B04"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:beta2:*:*:*:*:*:*","matchCriteriaId":"E0FF092C-EC93-4371-820B-3A25C0BEF666"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:rc1:*:*:*:*:*:*","matchCriteriaId":"3149C6F6-9C91-4A8E-BEC0-B476D9B3CF1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:rc2:*:*:*:*:*:*","matchCriteriaId":"DB1E5589-AD4C-4535-B4E2-12665B8A6C45"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:rc3:*:*:*:*:*:*","matchCriteriaId":"A8705011-0A2A-43CD-8FA8-D09DE0DFB586"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:rc4:*:*:*:*:*:*","matchCriteriaId":"68E4D950-4F4E-4323-B18B-EEFCDB8F5D54"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:unstable1:*:*:*:*:*:*","matchCriteriaId":"F75AD2A4-8CFB-4598-9D7B-C311731C49C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:unstable2:*:*:*:*:*:*","matchCriteriaId":"21599548-D154-4AC6-9700-2AD02281B097"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.0:unstable3:*:*:*:*:*:*","matchCriteriaId":"990E06E3-3164-4A83-AAC0-64E39B02BD65"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.1:*:*:*:*:*:*:*","matchCriteriaId":"8D9B12B8-1A47-48CD-9439-842EC59C8560"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.2:*:*:*:*:*:*:*","matchCriteriaId":"AA3972A6-A0CC-4F61-A6FF-D0B8B5139559"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:6.x-3.x:dev:*:*:*:*:*:*","matchCriteriaId":"5AF42B77-B1EB-4B06-941C-FC414568E0BC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B1170D-AD33-4C7A-892D-63AC71B032CF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:*:*:*:*:*:*:*","matchCriteriaId":"C0401AB3-8CD3-4191-BD67-FDEF8AC389E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:beta1:*:*:*:*:*:*","matchCriteriaId":"D8F3E689-9099-4B52-A521-C9933CEC3A83"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:beta2:*:*:*:*:*:*","matchCriteriaId":"FF87F785-B660-4471-8525-8C38E4B1ED0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:rc1:*:*:*:*:*:*","matchCriteriaId":"92E55B94-035B-4C95-844A-994FC9098DA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:rc2:*:*:*:*:*:*","matchCriteriaId":"F178FBC3-11A0-4341-B930-7FD45F2E9391"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:rc3:*:*:*:*:*:*","matchCriteriaId":"AFC242C4-3283-4D6D-B69F-869E971D2102"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:rc4:*:*:*:*:*:*","matchCriteriaId":"B1A2F122-6D2C-42BC-8DA5-BBD19CE5FC5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:rc5:*:*:*:*:*:*","matchCriteriaId":"57C52124-9EF2-448B-B768-A9CAAAF4F9A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.0:rc6:*:*:*:*:*:*","matchCriteriaId":"35055934-F01E-44DF-906B-B0B23BDBE9EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.1:*:*:*:*:*:*:*","matchCriteriaId":"82C2C7C6-AE59-4BCF-8296-591D6DBFD907"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.2:*:*:*:*:*:*:*","matchCriteriaId":"840E97FC-3BA3-43C9-AB0B-49267D75F529"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.3:*:*:*:*:*:*:*","matchCriteriaId":"41060BF1-EFD1-449D-8D41-C6B898058DFE"},{"vulnerable":true,"criteria":"cpe:2.3:a:marc_ingram:services:7.x-3.x:dev:*:*:*:*:*:*","matchCriteriaId":"32EBEE31-40E3-40A2-8FCB-EF726A1451EA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*","matchCriteriaId":"F8B1170D-AD33-4C7A-892D-63AC71B032CF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5586","Ordinal":"1","Title":"CVE-2012-5586","CVE":"CVE-2012-5586","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5586","Ordinal":"1","NoteData":"The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the \"access user profiles\" permission to access arbitrary users' emails via vectors related to the \"user index method\" and \"the path to the user resource.\"","Type":"Description","Title":"CVE-2012-5586"},{"CveYear":"2012","CveId":"5586","Ordinal":"2","NoteData":"2012-12-26","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5586","Ordinal":"3","NoteData":"2013-02-26","Type":"Other","Title":"Modified"}]}}}