The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2012-10-31T16:00:00Z
Updated: 2024-09-17T04:05:03.060Z
Reserved: 2012-08-21T00:00:00Z
Link: CVE-2012-4483
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-10-31T16:55:02.857
Modified: 2024-11-21T01:42:59.060
Link: CVE-2012-4483
Redhat
No data.