{"id":"CVE-2012-2153","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-2153","summary":"Drupal improper access restrictions","details":"Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a \"contributed node access module,\" which allows remote authenticated users with the \"Access the content overview page\" permission to read all published nodes by accessing the admin/content page.","published":"2022-05-17T04:56:41Z","modified":"2023-11-08T03:57:05.005987Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"7.14"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2153"},{"type":"WEB","url":"https://web.archive.org/web/20150523060428/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2013:074/?name=MDVSA-2013:074"},{"type":"WEB","url":"https://web.archive.org/web/20200229101926/http://www.securityfocus.com/bid/53362"},{"type":"WEB","url":"http://drupal.org/drupal-7.14"},{"type":"WEB","url":"http://drupal.org/node/1557938"},{"type":"WEB","url":"http://drupal.org/node/1558478"},{"type":"WEB","url":"http://drupalcode.org/project/drupal.git/commit/c6d2b8311b82fe78d18732f01a68ceca3dea50af"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:05.005987Z"}}