CVE-2009-0382
Description
Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Drupal's i18n Translation 5.x before 2.5 lets users with 'translate node' permission bypass access controls and read unpublished nodes.
Vulnerability
The Internationalization (i18n) Translation module for Drupal 5.x, versions prior to 5.x-2.5, contains an unspecified access bypass vulnerability [1]. The module allows users with the translate node permission to create translations of existing content (nodes) by copying the original node's content into a new translation node. The flaw permits a user who can translate nodes to also view the content of unpublished nodes, even if they lack explicit permission to view unpublished nodes [1].
Exploitation
A remote attacker must have the translate node permission assigned to their Drupal user account. No other special network position or authentication is required beyond a valid Drupal login with that permission. The attacker can exploit the vulnerability by initiating the translation process on an unpublished node, which copies the node's content—thereby revealing the unpublished content to the attacker [1]. The exact vectors are unspecified, but the access bypass occurs during the translation operation.
Impact
Successful exploitation leads to unauthorized information disclosure. A user with translate node privileges can read the content of unpublished nodes, bypassing standard Drupal access controls that should restrict such viewing. The attacker gains read access to sensitive or draft content that would otherwise remain hidden from them. The impact is limited to information disclosure; no modification or deletion of nodes is reported.
Mitigation
The vulnerability is fixed in Internationalization (i18n) 5.x-2.5, released on January 14, 2009 [1]. Users of 5.x-2.x should upgrade to 5.x-2.5 immediately. Drupal core is not affected; only sites using the contributed i18n module are vulnerable. No workaround is provided. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:drupal:internationalization:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:drupal:internationalization:*:*:*:*:*:*:*:*range: <=5.x-2.3
- cpe:2.3:a:drupal:internationalization:5.x-1.1:*:*:*:*:*:*:*
- Range: <5.x-2.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- drupal.org/node/358958nvdPatchVendor Advisory
- secunia.com/advisories/33549nvdVendor Advisory
- www.securityfocus.com/bid/33283nvd
News mentions
0No linked articles in our index yet.