« Volver al listado

CVE-2014-9504

Estado: ModificadaAlta (7.5)—

The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-9504",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-01T17:29:01.010",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/01/04/6",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99657",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2394979",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2395045",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/01/04/6",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99657",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2394979",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2395045",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance."
    },
    {
      "lang": "es",
      "value": "El módulo OG Subgroups, cuando se utiliza con el módulo Open Atrium en versiones 7.x-2.x anteriores a las 7.x-2.26 para Drupal, permite que los atacantes remotos accedan a grupos child a través de vectores relacionados con membresías mediante herencia."
    }
  ],
  "lastModified": "2026-06-17T00:18:29.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE3C0F8F-550C-43E2-A68C-1232E5BB03D4",
              "versionEndExcluding": "7.x-2.26",
              "versionStartIncluding": "7.x-2.0"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:alpha1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF3160D6-D8F4-4492-B4BC-8CEBB30E8CF0"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:alpha2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AFFF66B-966F-44E2-937A-A9AF4A8BA098"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:alpha3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FBA852F-2C9D-4705-9EA8-7C92F97E0C49"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:alpha4:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2A658D4-DD9D-4409-B8BB-99989C1EFF96"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:alpha5:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8301DB55-6225-44F1-B277-4BAE410655FA"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:beta1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "606B1F8B-0AE4-4757-8558-EE197D9F60D5"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:beta2:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EA8F582-1316-4470-90F7-A74387058CD2"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:beta3:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBE88918-2639-4A51-AF85-8AA513FE807B"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:beta4:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B22E63ED-6B41-4DF5-9D70-444EA53F7E99"
            },
            {
              "criteria": "cpe:2.3:a:open_atrium_project:open_atrium:7.x-2.0:rc1:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB94D1CA-963D-4AF3-B0E4-4DC42D4CE736"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}