The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does not properly enforce intended node access restrictions, which might allow remote attackers to obtain sensitive information via the recent comments listing.
2012-10-31T16:55:02.857
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | acquia | commons | 6.x-2.4 | Yes |
| Application | acquia | commons | 6.x-2.5 | Yes |
| Application | acquia | commons | 6.x-2.6 | Yes |
| Application | acquia | commons | 6.x-2.7 | Yes |
| Application | acquia | commons | 6.x-2.x | Yes |
| Application | drupal | drupal | - | No |