« Volver al listado

CVE-2013-4226

Estado: ModificadaMedia (6.5)—

El módulo Authenticated User Page Caching (Authcache) versiones 7.x-1.x anteriores a 7.x-1.5 para Drupal, no restringe apropiadamente el acceso a las páginas almacenadas en caché, lo que permite a atacantes remotos con la misma combinación de roles que el superusuario, obtener información confidencial por medio de las páginas almacenadas en caché del superusuario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4226",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Authenticated User Page Caching (Authcache) module",
          "versions": [
            {
              "status": "affected",
              "version": "7.x-1.x before 7.x-1.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-02-18T19:15:11.647",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/08/10/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2058165",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2059589",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/08/10/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2058165",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2059589",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser."
    },
    {
      "lang": "es",
      "value": "El módulo Authenticated User Page Caching (Authcache) versiones 7.x-1.x anteriores a 7.x-1.5 para Drupal, no restringe apropiadamente el acceso a las páginas almacenadas en caché, lo que permite a atacantes remotos con la misma combinación de roles que el superusuario, obtener información confidencial por medio de las páginas almacenadas en caché del superusuario."
    }
  ],
  "lastModified": "2026-06-16T23:56:50.893",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:authenticated_user_page_caching:7.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "701EA346-B978-490A-8A5E-A147E4D2E30C"
            },
            {
              "criteria": "cpe:2.3:a:drupal:authenticated_user_page_caching:7.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F49C0EA-9917-4741-ADA7-9B7B3BBB7F9D"
            },
            {
              "criteria": "cpe:2.3:a:drupal:authenticated_user_page_caching:7.x-1.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "700C4BE3-8E78-4F42-8695-FD687266C88F"
            },
            {
              "criteria": "cpe:2.3:a:drupal:authenticated_user_page_caching:7.x-1.3:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E44833D3-5B1B-4495-BD02-D0C3A91841B4"
            },
            {
              "criteria": "cpe:2.3:a:drupal:authenticated_user_page_caching:7.x-1.4:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D185DEF5-175C-47F6-84DD-16596D12EE13"
            },
            {
              "criteria": "cpe:2.3:a:drupal:authenticated_user_page_caching:7.x-1.5:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0A3964B-745F-4E18-B654-05BBA245D305"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}