The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://drupal.org/node/2059589 | vendor advisory |
http://www.openwall.com/lists/oss-security/2013/08/10/1 | third party advisory mailing list |
https://drupal.org/node/2058165 | release notes vendor advisory |