The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-10-31T16:00:00Z

Updated: 2024-09-17T04:05:03.060Z

Reserved: 2012-08-21T00:00:00Z

Link: CVE-2012-4483

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2012-10-31T16:55:02.857

Modified: 2012-11-13T05:00:00.000

Link: CVE-2012-4483

cve-icon Redhat

No data.