CVE-2015-2559: Debian Linux

Low severity, CVSS 3.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Drupal Drupal: from 6.0, before 6.35 (fixed in 6.35); from 7.0, before 7.35 (fixed in 7.35)

Published 2015-03-25. Last modified 2026-06-17.