Are all Drupal 7.2x sites NON PCI compliant because of CVE-2011-2687, the node access bypass threat ?
Posted by andyg8 on June 8, 2014 at 11:54am
Hi team,
Sorry if this is in the wrong place, but extensive Googling couldn't find an answer.
We've just had a PCI compliance scan done by Trustwave, which says we need to fix CVE-2011-2687,
node-access-bypass insecurity, which was fixed in Drupal 7.3. See: https://drupal.org/node/1204582.
But the last release of Drupal 7.3 was in 2011!
And Drupal.org home page says that 7.28 is the current release.
So does this mean every Drupal site in the world running the 7.2x branch
including 7.28 is not PCI compliant?