| Summary: |
CVE-2015-3231 CVE-2015-3232 CVE-2015-3233 CVE-2015-3234 drupal: several issues fixed in 7.38 and 6.36 (SA-CORE-2015-002) |
| Product: |
[Other] Security Response
|
Reporter: |
Vasyl Kaigorodov <vkaigoro> |
| Component: |
vulnerability | Assignee: |
Red Hat Product Security <security-response-team> |
| Status: |
CLOSED
WONTFIX
|
QA Contact: |
|
| Severity: |
high
|
Docs Contact: |
|
| Priority: |
high
|
|
|
| Version: |
unspecified | CC: |
ccoleman, dmcphers, gwync, hello, jialiu, joelsmith, jokerman, jsmith.fedora, kseifried, lmeyer, mmccomas, shawn, stickster, sven
|
| Target Milestone: |
--- | Keywords: |
Security |
| Target Release: |
--- | |
|
| Hardware: |
All | |
|
| OS: |
Linux | |
|
| Whiteboard: |
|
|
Fixed In Version:
|
|
Doc Type:
|
Bug Fix
|
|
Doc Text:
|
|
Story Points:
|
---
|
|
Clone Of:
|
|
Environment:
|
|
|
Last Closed:
|
2015-07-10 04:39:28 UTC
|
Type:
|
---
|
|
Regression:
|
---
|
Mount Type:
|
---
|
|
Documentation:
|
---
|
CRM:
|
|
|
Verified Versions:
|
|
Category:
|
---
|
|
oVirt Team:
|
---
|
RHEL 7.3 requirements from Atomic Host:
|
|
|
Cloudforms Team:
|
---
|
Target Upstream Version:
|
|
|
Embargoed:
|
|
| |
| Bug Depends On: |
1234427, 1234428, 1234429, 1234430, 1241765
|
|
|
| Bug Blocks: |
|
|
|
Several issues were fixed in Drupal 7.38 and Drupal 6.36 core modules: Impersonation (OpenID module - Drupal 6 and 7): CVE-2015-3234 Open redirect (Field UI module - Drupal 7): CVE-2015-3232 Open redirect (Overlay module - Drupal 7: CVE-2015-3233 Information disclosure (Render cache system - Drupal 7): CVE-2015-3231 External References: https://www.drupal.org/SA-CORE-2015-002