The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/72676 | vdb entry |
https://www.drupal.org/node/2428857 | patch |
http://www.openwall.com/lists/oss-security/2015/04/25/6 | mailing list |
https://www.drupal.org/node/2428855 | patch |
https://www.drupal.org/node/2428863 | vendor advisory |