The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/04/25/6 | mailing list |
https://www.drupal.org/node/2444861 | patch |
https://www.drupal.org/node/2428851 | vendor advisory |
http://www.securityfocus.com/bid/72677 | vdb entry |