« Volver al listado

CVE-2009-3568

Estado: ModificadaMedia (5)—

Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-3568",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-10-06T20:30:00.250",
  "references": [
    {
      "url": "http://drupal.org/node/579280",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/579290",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/579292",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/36787",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/58177",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/36429",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/579280",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://drupal.org/node/579290",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://drupal.org/node/579292",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/36787",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/58177",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36429",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed."
    },
    {
      "lang": "es",
      "value": "El modulo de Drupal, Comment RSS v5.x anteriores a v5.x-2.2 y v6.x anteriores a  v6.x-2.2, no hace cumplir correctamente los permisos cuando un enlace se añade a un feed RSS, lo que permite a atacantes remotos obtener el titulo del nodo y posiblemente mas información sensible mediante la lectura del feed."
    }
  ],
  "lastModified": "2026-06-16T23:11:55.050",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dave_reid:commentrss:5.x-2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0891335F-6BBE-4517-947A-2D329A4582FF"
            },
            {
              "criteria": "cpe:2.3:a:dave_reid:commentrss:6.x-2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC9BF285-7CB3-4B6D-B422-74A1746BEC8F"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "725FC7B8-6EA5-4F25-88A3-790B1758467D"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20322FF6-A0D4-4D09-A7B1-06E3456EB91C"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B37843CC-5550-4807-BFD6-8125788718D6"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19F8DFEF-46C8-4197-A1F4-722A8B6B5029"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:5.x-2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2D753EC-88C3-43D6-8E17-DAAEA378445C"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:5.x-2.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94E8ACC7-9719-442F-810A-B76205C4F2DC"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:6.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEA997EE-B25C-4C24-B257-ECB13899C323"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:6.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E707A50-E544-466C-9D09-A16E47450D29"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:6.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36C84085-3549-441C-A714-729C8369B232"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:6.x-2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A672F19-3D97-4372-B038-D8418C1C54FD"
            },
            {
              "criteria": "cpe:2.3:a:gabor_hojtsy:commentrss:6.x-2.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B9DB9CF-4F49-4C36-A16C-983866ADA337"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}