The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2016/07/13/4 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/07/13/7 | Mailing List Third Party Advisory |
| https://www.drupal.org/node/2749333 | Vendor Advisory |
| https://www.drupal.org/SA-CORE-2016-002 | Vendor Advisory |
| http://www.securityfocus.com/bid/91230 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2016-09-09 07:05
Updated : 2016-11-28 12:31
NVD link : CVE-2016-6212
Mitre link : CVE-2016-6212
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
drupal
- drupal


