CVE-2012-0826
Published: 28 October 2013
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.
Priority
Status
Package | Release | Status |
---|---|---|
drupal6 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Ignored
(end of life)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Ignored
(end of life)
|
|
quantal |
Not vulnerable
(6.26-1.1ubuntu1)
|
|
raring |
Not vulnerable
(6.26-1.1ubuntu1)
|
|
saucy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(6.23)
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
drupal7 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Not vulnerable
(7.12-1)
|
|
quantal |
Not vulnerable
(7.14-1)
|
|
raring |
Not vulnerable
(7.14-1)
|
|
saucy |
Not vulnerable
(7.14-1)
|
|
trusty |
Not vulnerable
(7.14-1)
|
|
upstream |
Released
(7.11)
|
|
utopic |
Not vulnerable
(7.14-1)
|
|
vivid |
Not vulnerable
(7.14-1)
|
|
wily |
Not vulnerable
(7.14-1)
|
|
xenial |
Not vulnerable
(7.14-1)
|
|
yakkety |
Not vulnerable
(7.14-1)
|
|
zesty |
Not vulnerable
(7.14-1)
|