Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14840

Опубликовано: 17 дек. 2025
Источник: redhat
CVSS3: 2.2
EPSS Низкий

Описание

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.

A flaw was found in the Drupal Http Client Manager module. This module, which allows administrators to configure HTTP requests, does not adequately separate data from request operations. This oversight could potentially lead to the disclosure of sensitive information under specific, uncommon circumstances.

Отчет

This vulnerability doesn't affect any supported Red Hat product.

Дополнительная информация

Статус:

Low
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2423425drupal: Drupal Http Client Manager: Information disclosure due to insufficient data separation

EPSS

Процентиль: 18%
0.00263
Низкий

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
7 месяцев назад

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.

github
7 месяцев назад

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.

EPSS

Процентиль: 18%
0.00263
Низкий

2.2 Low

CVSS3