Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 376689

Summary: <www-apps/drupal-7.7: Access bypass in private file fields on comments.
Product: Gentoo Security Reporter: Peter Volkov (RETIRED) <pva>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://drupal.org/node/1231510
Whiteboard: ~3 [noglsa]
Package list:
Runtime testing required: ---

Description Peter Volkov (RETIRED) gentoo-dev 2011-07-28 08:49:24 UTC
Description
Access bypass in private file fields on comments.

Drupal 7 contains two new features: the ability to attach File upload fields to
any entity type in the system and the ability to point individual File upload
fields to the private file directory.

If a Drupal site is using these features on comments, and the parent node is
denied access (either by a node access module or by being unpublished), the
file attached to the comment can still be downloaded by non-privileged users if
they know or guess its direct URL.

This issue affects Drupal 7.x only.
Versions affected

    Drupal 7.x before version 7.5.
Comment 1 Peter Volkov (RETIRED) gentoo-dev 2011-07-28 08:55:06 UTC
7.7 that fixes this issue is in the tree.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-08-17 21:09:47 UTC
Great, thanks, Peter. Closing noglsa for ~arch only package.