The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122308.html | vendor advisory |
https://drupal.org/node/2113317 | patch vendor advisory |
https://drupal.org/node/2112785 | patch |
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/121433.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/122298.html | vendor advisory |
https://drupal.org/node/2112791 | patch |