Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability
BID:25364
Info
Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability
| Bugtraq ID: | 25364 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-4436 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Derek Wright of the Drupal security team is credited with the discovery of this vulnerability. |
| Vulnerable: |
Drupal Project issue tracking 4.7 2.2 Drupal Project issue tracking 4.7 1.2 Drupal Project issue tracking 5.0-0.2beta Drupal Project issue tracking 5.0-0.1beta Drupal Project issue tracking 5.0-0.1 Drupal Project issue tracking 4.7.0-2.3 Drupal Project issue tracking 4.7.0-2.1 Drupal Project issue tracking 4.7.0-2.0 Drupal Project issue tracking 4.7.0-1.3 Drupal Project issue tracking 4.7.0-1.1 Drupal Project issue tracking 4.7.0-1.0 Drupal Project issue tracking 4.7.0 Drupal Project 5.0 1-beta Drupal Project 4.7 2.2 Drupal Project 4.7 2-2 Drupal Project 4.7 1.2 Drupal Project 5.0-0.1 Drupal Project 4.7.0-2.1 Drupal Project 4.7.0-2.0 Drupal Project 4.7.0-1.1 Drupal Project 4.7.0-1.0 Drupal Project 4.7.0 |
| Not Vulnerable: |
Drupal Project issue tracking 5.0-1.0 Drupal Project issue tracking 4.7.0-2.4 Drupal Project issue tracking 4.7.0-1.4 Drupal Project 5.0-1.0 Drupal Project 4.7.0-2.3 Drupal Project 4.7.0-1.3 |
Discussion
Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability
The Drupal Project and Project Issue Tracking modules are prone to a security-bypass vulnerability because of an access-validation error in the affected modules.
An attacker can exploit this issue to bypass security restrictions and gain access to sensitive information that may lead to other attacks.
The Drupal Project and Project Issue Tracking modules are prone to a security-bypass vulnerability because of an access-validation error in the affected modules.
An attacker can exploit this issue to bypass security restrictions and gain access to sensitive information that may lead to other attacks.
Exploit / POC
Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Drupal Project 5.0-0.1
Drupal Project 4.7.0-2.1
Drupal Project issue tracking 4.7.0-1.3
Drupal Project issue tracking 4.7.0-2.1
Drupal Project 4.7.0-1.1
Drupal Project issue tracking 5.0-0.1
Drupal Project issue tracking 4.7.0-1.0
Drupal Project 4.7.0-1.0
Drupal Project issue tracking 4.7.0-1.1
Drupal Project issue tracking 4.7.0-2.0
Drupal Project 4.7.0-2.0
Drupal Project issue tracking 4.7.0-2.3
Drupal Project 4.7 2.2
Drupal Project issue tracking 4.7 1.2
Drupal Project issue tracking 4.7 2.2
Drupal Project 4.7 1.2
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Drupal Project 5.0-0.1
-
Drupal project-5.x-1.0.tar.gz
http://ftp.drupal.org/files/projects/project-5.x-1.0.tar.gz
Drupal Project 4.7.0-2.1
-
Drupal project-4.7.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project-4.7.x-2.3.tar.gz
Drupal Project issue tracking 4.7.0-1.3
-
Drupal project_issue-4.7.x-1.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.4.tar.gz
Drupal Project issue tracking 4.7.0-2.1
-
Drupal project_issue-4.7.x-2.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.4.tar.gz
Drupal Project 4.7.0-1.1
-
Drupal project-4.7.x-1.3.tar.gz
http://ftp.drupal.org/files/projects/project-4.7.x-1.3.tar.gz
Drupal Project issue tracking 5.0-0.1
-
Drupal project_issue-5.x-1.0.tar.gz
http://ftp.drupal.org/files/projects/project_issue-5.x-1.0.tar.gz
Drupal Project issue tracking 4.7.0-1.0
-
Drupal project_issue-4.7.x-1.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.4.tar.gz
Drupal Project 4.7.0-1.0
-
Drupal project-4.7.x-1.3.tar.gz
http://ftp.drupal.org/files/projects/project-4.7.x-1.3.tar.gz
Drupal Project issue tracking 4.7.0-1.1
-
Drupal project_issue-4.7.x-1.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.4.tar.gz
Drupal Project issue tracking 4.7.0-2.0
-
Drupal project_issue-4.7.x-2.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.4.tar.gz
Drupal Project 4.7.0-2.0
-
Drupal project-4.7.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project-4.7.x-2.3.tar.gz
Drupal Project issue tracking 4.7.0-2.3
-
Drupal project_issue-4.7.x-2.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.4.tar.gz
Drupal Project 4.7 2.2
-
Drupal project-4.7.x-2.3.tar.gz
http://ftp.drupal.org/files/projects/project-4.7.x-2.3.tar.gz
Drupal Project issue tracking 4.7 1.2
-
Drupal project_issue-4.7.x-1.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-1.4.tar.gz
Drupal Project issue tracking 4.7 2.2
-
Drupal project_issue-4.7.x-2.4.tar.gz
http://ftp.drupal.org/files/projects/project_issue-4.7.x-2.4.tar.gz
Drupal Project 4.7 1.2
-
Drupal project-4.7.x-1.3.tar.gz
http://ftp.drupal.org/files/projects/project-4.7.x-1.3.tar.gz
References
Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability
References:
References:
- Project 4.7.x-1.3 Release Notes (Drupal)
- Project 4.7.x-2.3 Release Notes (Drupal)
- Project 5.x-1.0 Release Notes (Drupal)
- Project_issue 4.7.x-1.4 Release Notes (Drupal)
- Project_issue 4.7.x-2.4 Release Notes (Drupal)
- Project_issue 5.x-1.0 Release Notes (Drupal)
- Vendor Homepage (Drupal)
- Project and Project issue tracking - Access bypass (Drupal)