« Volver al listado

CVE-2009-3442

Estado: ModificadaMedia (5)—

El módulo "Meta tags" (también conocido como Nodewords) en versiones anteriores a la v6.x-1.1 para Drupal no respeta apropiadamente los permisos durante la asignación de meta-etiquetas de un nodo, lo que permite a atacantes remotos obtener información confidencial a través de vectores de ataque sin especificar.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-3442",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-09-28T22:30:00.937",
  "references": [
    {
      "url": "http://drupal.org/node/585706",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/585710",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/58314",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/36841",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/36506",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53452",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/585706",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://drupal.org/node/585710",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/58314",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/36841",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36506",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53452",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows remote attackers to obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo \"Meta tags\" (también conocido como Nodewords) en versiones anteriores a la v6.x-1.1 para Drupal no respeta apropiadamente los permisos durante la asignación de meta-etiquetas de un nodo, lo que permite a atacantes remotos obtener información confidencial a través de vectores de ataque sin especificar."
    }
  ],
  "lastModified": "2026-06-16T23:11:36.723",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:5.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC6A4DC0-C9E7-48DE-B651-0C49F99D7B50"
            },
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:5.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCA8D60C-FA65-4A1C-9C25-4CB9945D2D46"
            },
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:5.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96B8D101-EB07-4F8B-B865-6E76F3C13954"
            },
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:5.x-1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41D06D59-E500-463F-B36F-9CA710FF57BF"
            },
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:5.x-1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BA1D598-96B5-4E74-BB36-6204BBB32EB1"
            },
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:5.x-1.x-dev:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1205E96-611F-40B1-B46B-E6F7C67922E6"
            },
            {
              "criteria": "cpe:2.3:a:ariel_barreiro:meta_tags:6.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A416A6F4-CF01-4822-BC00-B808BE4C3794"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}