Candidate: CVE-2014-1476 PublicDate: 2014-01-24 18:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1476 http://www.openwall.com/lists/oss-security/2014/01/16 https://drupal.org/SA-CORE-2014-001 Description: The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_drupal7: upstream_drupal7: released (7.26-1) lucid_drupal7: DNE precise_drupal7: ignored (reached end-of-life) precise/esm_drupal7: DNE (precise was needed) quantal_drupal7: ignored (reached end-of-life) raring_drupal7: ignored (reached end-of-life) saucy_drupal7: ignored (reached end-of-life) trusty_drupal7: not-affected (7.26-1) trusty/esm_drupal7: DNE (trusty was not-affected [7.26-1]) utopic_drupal7: not-affected (7.26-1) vivid_drupal7: not-affected (7.26-1) vivid/stable-phone-overlay_drupal7: DNE vivid/ubuntu-core_drupal7: DNE wily_drupal7: not-affected (7.26-1) xenial_drupal7: not-affected (7.26-1) yakkety_drupal7: not-affected (7.26-1) zesty_drupal7: not-affected (7.26-1) devel_drupal7: not-affected (7.26-1)