Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 988
BDU:2024-11232
Уязвимость модуля Comment CMS-системы Drupal, позволяющая нарушителю вызвать отказ в обслуживании
GHSA-62cf-jvpp-48q6
Drupal Denial of Service vulnerability
CVE-2024-22362
Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.
CVE-2024-22362
Drupal contains a vulnerability with improper handling of structural e ...
CVE-2024-22362
Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.
GHSA-rjqg-3h9m-fx5x
Cache poisoning in drupal/core
CVE-2023-5256
In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected.
CVE-2023-5256
In certain scenarios, Drupal's JSON:API module will output error backt ...
CVE-2023-5256
In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected.
GHSA-8849-cv9f-vccm
Access bypass in Drupal core
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2024-11232 Уязвимость модуля Comment CMS-системы Drupal, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-62cf-jvpp-48q6 Drupal Denial of Service vulnerability | 0% Низкий | почти 2 года назад | ||
CVE-2024-22362 Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-22362 Drupal contains a vulnerability with improper handling of structural e ... | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-22362 Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-rjqg-3h9m-fx5x Cache poisoning in drupal/core | 1% Низкий | около 2 лет назад | ||
CVE-2023-5256 In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
CVE-2023-5256 In certain scenarios, Drupal's JSON:API module will output error backt ... | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
CVE-2023-5256 In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-8849-cv9f-vccm Access bypass in Drupal core | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу