Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rjqg-3h9m-fx5x

Опубликовано: 28 сент. 2023
Источник: github
Github: Прошло ревью

Описание

Cache poisoning in drupal/core

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.

This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API.

The core REST and contributed GraphQL modules are not affected.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.7.0, < 9.5.11

9.5.11

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.0.11

10.0.11

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 10.1.0, < 10.1.4

10.1.4

EPSS

Процентиль: 81%
0.01615
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected.

CVSS3: 7.5
nvd
больше 1 года назад

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected.

CVSS3: 7.5
debian
больше 1 года назад

In certain scenarios, Drupal's JSON:API module will output error backt ...

EPSS

Процентиль: 81%
0.01615
Низкий

Дефекты

CWE-200