CVE-2015-3231: Debian Linux
Medium severity, CVSS 4.0. EPSS: 1.7% chance of exploitation in the next 30 days.
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
Published 2015-06-22. Last modified 2026-06-17.