The Drupal reports that Drupal 7.12 contains the following vulnerability: Access bypass - content administration CVE: CVE-2012-2153 Drupal core provides the ability to list nodes on a site at admin/content. Drupal core failed to confirm a user viewing that page had access to each node in the list. This vulnerability only concerns sites running a contributed node access module and is mitigated by the fact that users must have a role with the "Access the content overview page" permission. Unpublished nodes were not displayed to users who only had the "Access the content overview page" permission. External reference: http://drupal.org/node/1557938
Created drupal7 tracking bugs for this issue Affects: fedora-all [bug 956481]
Created drupal7 tracking bugs for this issue Affects: epel-all [bug 956483]