oss-sec mailing list archives

Re: CVE Request for Drupal contrib modules


From: Kurt Seifried <kseifried () redhat com>
Date: Thu, 28 Mar 2013 18:53:31 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 03/28/2013 02:00 PM, Forest Monsen wrote:
Hi there,

I'd like to request CVE identifiers for:

SA-CONTRIB-2013-036 - Zero Point - Cross Site Scripting (XSS) 
http://drupal.org/node/1954588

Please use CVE-2013-1905 for this issue.

SA-CONTRIB-2013-037 - Rules - Cross Site Scripting (XSS) 
http://drupal.org/node/1954592

Please use CVE-2013-1906 for this issue.

SA-CONTRIB-2013-038 - Commons Groups - Access bypass & Privilege 
escalation http://drupal.org/node/1954764

Please use CVE-2013-1907 for this issue.

SA-CONTRIB-2013-039 - Commons Wikis - Access bypass & Privilege
escalation http://drupal.org/node/1954766

Please use CVE-2013-1908 for this issue.

Thanks!

Forest


- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)

iQIcBAEBAgAGBQJRVOYLAAoJEBYNRVNeJnmT9coP/2P1CJEFrRGo8NMq9AVR/SvA
GWDL+zK16Dejqm+EoYA9pb1r4uh40igN77Akj1UgbQJtQn3EpIuMpzzGojZFgwwo
2YSuykWx4rWXDEYrhMW+BzPARZgOcM54I7l+EgBd0+nu9dKWrX64HGIlP7RE01RE
lRMyltw+qnBanJMGHcIUo96P00co6AMoGh02Wj7pcce87oH353bU0yWILhNc/dve
iEkO4s0w3E30TbFtJJk3WKDNoORjfRB9ix7CSOeIz99vJZrG4B9wqH6l+rnNIpGC
Cp4PQPrJ4e0muIqVgW8CKytBM6GBlcb8+/s9G8yjUUYuNGnd496+b7PMtHIdq4r4
E80oJ4tOiHTA5kebNCXHQs9YAAuMOOodBFnJezffoO5ZBXgc+31s5Pv1rZTJIdJ5
yE/5bonCigNSHfuWQi34um6P4ytHGTkxZzEiwZoWnnSNaqHSSPBtSwz0uJJjix+O
SJWJiy9wcjcWZxGhQKLtnIk+K74UPrY41zc/e4XPT+JNeKIbljrVuATh67RsrUmU
tDO6tZ/slpQ1IsxuSWug4bCAwhydVNZ6vun83/wHPxAUPgPxvj4hlQQMX3OMuU2u
JOe6pekVuNa6fFq70oY8Xla0W4LX71Oe2Vwm6h4h4AkXCXDXNEyrwMehrYpvrF9w
leeXpkXSeJtPKAJIIN0Y
=fwxJ
-----END PGP SIGNATURE-----


Current thread: