LWN.net Logo

drupal7: restriction bypass

Package(s):drupal7 CVE #(s):CVE-2011-2687
Created:July 18, 2011 Updated:July 20, 2011
Description: From the Drupal advisory:

Listings showing nodes but not JOINing the node table show all nodes regardless of restrictions imposed by the node_access system. In core, this affects the taxonomy and the forum subsystem.

Alerts:
Fedora FEDORA-2011-8879 2011-06-30
Fedora FEDORA-2011-8878 2011-06-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds