The RESTful module 7.x-1.x before 7.x-1.3 for Drupal does not properly cache pages of authenticated users when using non-cookie authentication providers, which allows remote attackers to obtain sensitive information via unspecified vectors. <a href"https://cwe.mitre.org/data/definitions/524.html">CWE-524: Information Exposure Through Caching </a>
Publication date: Thu, 17 Sep 2015 21:59:00 +0000