« Volver al listado

CVE-2013-4498

Estado: ModificadaBaja (2.1)—

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4498",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-05-17T20:55:02.257",
  "references": [
    {
      "url": "http://seclists.org/oss-sec/2013/q4/210",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2118717",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://drupal.org/node/2118745",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/oss-sec/2013/q4/210",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2118717",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://drupal.org/node/2118745",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be \"orphaned\" and allows remote authenticated users with the \"access content\" permission to obtain sensitive information via vectors involving a rebuild access for the site or content."
    },
    {
      "lang": "es",
      "value": "El submódulo Spaces OG en el módulo Spaces 6.x-3.x anterior a 6.x-3.7 para Drupal no elimina debidamente contenido de espacios grupo grupo orgánico cuando utiliza la opción para trasladar a un grupo nuevo, lo que causa que el contenido quede 'huerfano' y permite a usuarios remotos autenticados con el permiso 'acceder a contenido' obtener información sensible a través de vectores involucrando un acceso de reconstrucción para el sitio o contenido."
    }
  ],
  "lastModified": "2026-06-16T23:57:20.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1CC67A4-5738-4B8F-BE5C-88CA25421429"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D25D0B7-B244-4B26-A12C-9EDD7819A2DA"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C47605FB-4CC3-4EB9-920B-26262B7A6A7D"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "459CB0BD-CAD0-4A0B-AD85-E95BF8A435F6"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BA90A0E-B5A0-4601-B0A3-0CE799E3F36F"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C425F11-21B1-4711-9DFD-D01E0552A85E"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6950379-D3E8-4EA7-85C8-9B8AFC866179"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E54DCB9-B15B-47C9-A615-E21732129089"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7B82BE1-7EBC-4FFB-A458-E8873D34A48E"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4152DF10-495C-4C41-8E3F-911556AE7533"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.0:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93285C66-DEE3-4DC7-A3EF-21DE03715C82"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F131660-BB9E-429D-9862-1302ACEB5E70"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8A86D65-402B-4D80-B774-294BC38572DE"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C87A533E-C7E7-4A32-8A66-D568183006B4"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34CCA764-00D8-4EED-95A2-AC7777149FFF"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B455425A-09F6-48F9-9399-1D3196EEFB95"
            },
            {
              "criteria": "cpe:2.3:a:florian_weber:spaces:6.x-3.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98FEE3FC-626B-4473-B9B3-CCA220D8CC5F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}