High severityNVD Advisory· Published Jul 27, 2011· Updated Apr 29, 2026
CVE-2011-2687
CVE-2011-2687
Description
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
drupal/corePackagist | >= 7.0, < 7.3 | 7.3 |
Affected products
19cpe:2.3:a:drupal:drupal:7.0:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:drupal:drupal:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha5:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha6:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:alpha7:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:dev:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:drupal:7.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- drupal.org/node/1204582nvdPatchVendor AdvisoryWEB
- secunia.com/advisories/45081nvdVendor Advisory
- secunia.com/advisories/45291nvdVendor Advisory
- github.com/advisories/GHSA-96vx-qf28-6f8mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-2687ghsaADVISORY
- bugs.debian.org/cgi-bin/bugreport.cginvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2011-July/062714.htmlnvdWEB
- lists.fedoraproject.org/pipermail/package-announce/2011-July/062722.htmlnvdWEB
- www.openwall.com/lists/oss-security/2011/07/11/2nvdWEB
- www.openwall.com/lists/oss-security/2011/07/12/16nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- web.archive.org/web/20110710024036/http://www.securityfocus.com/bid/48505ghsaWEB
- www.securityfocus.com/bid/48505nvd
News mentions
0No linked articles in our index yet.