Fedora Account System
Red Hat Associate
Red Hat Customer
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-9156 to the following vulnerability: Name: CVE-2014-9156 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9156 Assigned: 20141201 Reference: https://www.drupal.org/node/2304561 Reference: http://cgit.drupalcode.org/filefield/commit/?id=3a97fe1 Reference: https://www.drupal.org/node/2304517 The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file. The version containing the fix is already in Fedora and EPEL.