Bug 726222 (CVE-2011-2726, SA-CORE-2011-003)

Summary: drupal7: access bypass vulnerability in 7.x (SA-CORE-2011-003)
Product: [Other] Security Response Reporter: Othman Madjoudj <athmanem>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gwync, sdodson, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-11-03 22:09:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 726241, 726242, 726243    
Bug Blocks:    

Description Othman Madjoudj 2011-07-27 21:36:24 UTC
Advisory ID: DRUPAL-SA-CORE-2011-003
Project: Drupal core
Version: 7.x
Date: 2011-July-27
Security risk: Less critical
Exploitable from: Remote
Vulnerability: Access bypass

Details: http://drupal.org/node/1231510

Affected versions:
Drupal 7.x < 7.5

Solution:
Upgrade package to the latest versions: Drupal 7.5 or 7.6.

Note:

This affect both Fedora and EPEL package drupal7.

Comment 1 Vincent Danen 2011-07-27 22:34:03 UTC
Created drupal7 tracking bugs for this issue

Affects: epel-5 [bug 726241]
Affects: epel-6 [bug 726242]
Affects: fedora-all [bug 726243]

Comment 2 Scott Dodson 2011-11-03 22:09:30 UTC
Drupal 7 is currently at 7.8 with 7.9 release in the testing repos.