« Back to list

CVE-2008-3000

Status: ModifiedMedium (6.8)—

The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2008-3000",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-03T18:41:00.000",
  "references": [
    {
      "url": "http://drupal.org/node/269479",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/30618",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/29677",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43017",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/269479",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/30618",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/29677",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43017",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions."
    },
    {
      "lang": "es",
      "value": "El módulo Aggregation 5.x versiones anteriores a 5.x-4.4 para Drupal, nodo de acceso cuando se utilizan los módulos, no implementa apropiadamente el control de acceso, lo cual permite a atacantes remotos evitar restricciones previstas.\r\n\t\r\n"
    }
  ],
  "lastModified": "2026-06-16T22:54:54.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CF7A917-F319-4C29-A843-99A36B4A83B5"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A64D861C-D011-4CE6-B7C6-EEB4D7CCDC81"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CA6032D-27F3-4D80-8714-7F3ACA2E8836"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D6F71C3-0DCB-418A-8FD4-072D49CF9945"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F16FEA3A-265F-4332-A1A1-2879CA5682CC"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C57C2C4F-F4EC-4A25-841D-8597EB1582B9"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E8D028E-51F2-4BE9-99F3-85D1BE440FA7"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35595D9F-0DBB-45BF-86A8-6548FFBB588D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "Per Hyperlink Record 1026625, Drupal core is not affected. If you do not use the contributed Aggregation module, there is nothing you need to do.",
  "sourceIdentifier": "cve@mitre.org"
}