CVE-2012-2721
Estado: ModificadaMedia (6.8)—
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.60%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://drupal.org/node/1619736
- http://drupal.org/node/1619810
- http://drupalcode.org/project/og.git/commitdiff/1485708
- http://secunia.com/advisories/49397
- http://www.openwall.com/lists/oss-security/2012/06/14/3
- http://www.osvdb.org/82728
- http://www.securityfocus.com/bid/53838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76150
- http://drupal.org/node/1619736
- http://drupal.org/node/1619810
- http://drupalcode.org/project/og.git/commitdiff/1485708
- http://secunia.com/advisories/49397
- http://www.openwall.com/lists/oss-security/2012/06/14/3
- http://www.osvdb.org/82728
- http://www.securityfocus.com/bid/53838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76150
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-2721",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-06-27T00:55:04.957",
"references": [
{
"url": "http://drupal.org/node/1619736",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1619810",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupalcode.org/project/og.git/commitdiff/1485708",
"tags": [
"Exploit",
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/49397",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/14/3",
"source": "secalert@redhat.com"
},
{
"url": "http://www.osvdb.org/82728",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/53838",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76150",
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1619736",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/1619810",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupalcode.org/project/og.git/commitdiff/1485708",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49397",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/14/3",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/82728",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/53838",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76150",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the \"access content\" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact."
},
{
"lang": "es",
"value": "La vista por defecto en el módulo Organic Groups (OG) v6.x-2.x anteriores a v6.x-2.4 para Drupal no comprueba de forma adecuada los permisos cuando todos los usuario tienen eliminado el permiso de acceso al contenido (access content), lo que permite a atacantes remotos evitar los restricciones y posiblemente tenga otros impactos no determinados."
}
],
"lastModified": "2026-06-16T23:41:58.683",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "586989FC-FB44-4DF8-9ABB-9FE1BC9FC8FF"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F75F245C-CDC2-436A-94A4-3FDBC175CF5A"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD6163A1-1793-4261-ADE5-58F0A0AC5036"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61903138-CF7F-46EA-A3E1-DC0C324ACACA"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51E76179-60A8-4957-9A28-F28560874E3E"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25FD5736-4C27-47E9-A540-C06CD998A344"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D84F1641-CE86-4B96-9B28-77D70DDB3C27"
},
{
"criteria": "cpe:2.3:a:moshe_weitzman:organic_groups:6.x-2.x:dev:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "461DF120-E96F-448F-ADA6-A87FA93FA69D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secalert@redhat.com"
}