Drupal Permissions Privileges and Access Controls Vulnerability - CVE-2012-1591 - Vulnerability Database

Drupal Permissions Privileges and Access Controls Vulnerability - CVE-2012-1591

Medium
Reference: CVE-2012-1591
Title: Drupal Permissions Privileges and Access Controls Vulnerability
Overview:

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images which allows remote attackers to read private image styles.