Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. drupal/drupal
  4. ›
  5. CVE-2012-2153

CVE-2012-2153: Drupal improper access restrictions

May 17, 2022 (updated August 29, 2023)

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a “contributed node access module,” which allows remote authenticated users with the “Access the content overview page” permission to read all published nodes by accessing the admin/content page.

References

  • drupal.org/drupal-7.14
  • drupal.org/node/1557938
  • drupal.org/node/1558478
  • drupalcode.org/project/drupal.git/commit/c6d2b8311b82fe78d18732f01a68ceca3dea50af
  • github.com/advisories/GHSA-vpm6-h53m-x2xf
  • nvd.nist.gov/vuln/detail/CVE-2012-2153
  • web.archive.org/web/20150523060428/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2013:074/?name=MDVSA-2013:074
  • web.archive.org/web/20200229101926/http://www.securityfocus.com/bid/53362

Code Behaviors & Features

Detect and mitigate CVE-2012-2153 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.0 before 7.14

Fixed versions

  • 7.14

Solution

Upgrade to version 7.14 or above.

Impact 4 MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-264

Source file

packagist/drupal/drupal/CVE-2012-2153.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 17 Dec 2025 00:19:02 +0000.