node access bypass

Events happening in the community are now at Drupal community events on www.drupal.org.
andyg8's picture

Are all Drupal 7.2x sites NON PCI compliant because of CVE-2011-2687, the node access bypass threat ?

Hi team,

Sorry if this is in the wrong place, but extensive Googling couldn't find an answer.

We've just had a PCI compliance scan done by Trustwave, which says we need to fix CVE-2011-2687,
node-access-bypass insecurity, which was fixed in Drupal 7.3. See: https://drupal.org/node/1204582.

But the last release of Drupal 7.3 was in 2011!

And Drupal.org home page says that 7.28 is the current release.

So does this mean every Drupal site in the world running the 7.2x branch
including 7.28 is not PCI compliant?

Read more
Subscribe with RSS Syndicate content