The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request.
| Software | From | Fixed in |
|---|---|---|
| steven_jones / context | 6.x-3.0-beta1 | 6.x-3.0-beta1.x |
| steven_jones / context | 6.x-3.0-beta7 | 6.x-3.0-beta7.x |
| steven_jones / context | 6.x-3.0-beta5 | 6.x-3.0-beta5.x |
| steven_jones / context | 6.x-3.0-beta3 | 6.x-3.0-beta3.x |
| steven_jones / context | 6.x-3.0-rc2 | 6.x-3.0-rc2.x |
| steven_jones / context | 6.x-3.0-alpha2 | 6.x-3.0-alpha2.x |
| steven_jones / context | 6.x-3.0-alpha1 | 6.x-3.0-alpha1.x |
| steven_jones / context | 6.x-3.0-beta6 | 6.x-3.0-beta6.x |
| steven_jones / context | 6.x-3.0-beta8 | 6.x-3.0-beta8.x |
| steven_jones / context | 6.x-3.0 | 6.x-3.0.x |
| steven_jones / context | 6.x-3.0-beta4 | 6.x-3.0-beta4.x |
| steven_jones / context | 6.x-3.0-rc1 | 6.x-3.0-rc1.x |
| steven_jones / context | 6.x-3.0-beta2 | 6.x-3.0-beta2.x |
| steven_jones / context | 6.x-3.x-dev | 6.x-3.x-dev.x |
| steven_jones / context | 7.x-3.0-beta5 | 7.x-3.0-beta5.x |
| steven_jones / context | 7.x-3.0-beta2 | 7.x-3.0-beta2.x |
| steven_jones / context | 7.x-3.0-beta3 | 7.x-3.0-beta3.x |
| steven_jones / context | 7.x-3.0-alpha2 | 7.x-3.0-alpha2.x |
| steven_jones / context | 7.x-3.0-beta4 | 7.x-3.0-beta4.x |
| steven_jones / context | 7.x-3.0-alpha3 | 7.x-3.0-alpha3.x |
| steven_jones / context | 7.x-3.0-beta1 | 7.x-3.0-beta1.x |
| steven_jones / context | 7.x-3.0-alpha1 | 7.x-3.0-alpha1.x |
| steven_jones / context | 7.x-3.x-dev | 7.x-3.x-dev.x |