The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/64729 | third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/90215 | third party advisory vdb entry |
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126811.html | third party advisory vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2014-January/126816.html | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2014/01/09/3 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1050802 | third party advisory issue tracking |
https://www.drupal.org/node/2169595 | patch vendor advisory |