{
  "schema_version": "1.7.0",
  "id": "MGASA-2014-0322",
  "published": "2014-08-07T17:01:33Z",
  "modified": "2014-08-07T16:51:52Z",
  "summary": "Updated drupal packages fix security vulnerabilities",
  "details": "An information disclosure vulnerability was discovered in Drupal before 7.27.\nWhen pages are cached for anonymous users, form state may leak between\nanonymous users. Sensitive or private information recorded for one anonymous\nuser could thus be disclosed to other users interacting with the same form at\nthe same time (CVE-2014-2983).\n\nMultiple security issues in Drupal before 7.29, including a denial of service\nissue, an access bypass issue in the File module, and multiple cross-site\nscripting issues (CVE-2014-5019, CVE-2014-5020, CVE-2014-5021, CVE-2014-5022).\n\nDrupal has been updated to version 7.29, fixing this and other bugs.\n",
  "upstream": [
    "CVE-2014-2983",
    "CVE-2014-5019",
    "CVE-2014-5020",
    "CVE-2014-5021",
    "CVE-2014-5022"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2014-0322.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=13271"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/SA-CORE-2014-002"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/SA-CORE-2014-003"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/drupal-7.27"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/drupal-7.27-release-notes"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/drupal-7.28"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/drupal-7.28-release-notes"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/drupal-7.29"
    },
    {
      "type": "WEB",
      "url": "https://drupal.org/drupal-7.29-release-notes"
    },
    {
      "type": "WEB",
      "url": "https://www.debian.org/security/2014/dsa-2913"
    },
    {
      "type": "WEB",
      "url": "https://www.debian.org/security/2014/dsa-2983"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:3",
        "name": "drupal",
        "purl": "pkg:rpm/mageia/drupal?arch=source&distro=mageia-3"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.29-1.mga3"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "drupal",
        "purl": "pkg:rpm/mageia/drupal?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.29-1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
