The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/91230 | vdb entry |
https://www.drupal.org/node/2749333 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/07/13/4 | third party advisory mailing list |
https://www.drupal.org/SA-CORE-2016-002 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/07/13/7 | third party advisory mailing list |