The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://drupal.org/node/516104 | issue tracking third party advisory patch |
http://www.securityfocus.com/bid/36792 | patch vdb entry third party advisory broken link |
http://drupal.org/node/611128 | third party advisory patch |
http://drupal.org/node/609874 | release notes |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53897 | vdb entry third party advisory |
http://drupal.org/files/issues/filefield-node-access-fix-516104-3.patch | patch |
http://secunia.com/advisories/37130 | third party advisory broken link |