The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
{ "binaries": [ { "binary_version": "7.26-1ubuntu0.1+esm3", "binary_name": "drupal7" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-3231.json"