Description
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-6830)
Next.js Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2022-36046)
ReviveAdserver Other Vulnerability (CVE-2016-9471)
WordPress 7PK - Security Features Vulnerability (CVE-2016-10148)