Логотип exploitDog
bind:CVE-2022-25274
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25274

Количество 4

Количество 4

ubuntu логотип

CVE-2022-25274

около 2 лет назад

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-25274

около 2 лет назад

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-25274

около 2 лет назад

Drupal 9.3 implemented a generic entity access API for entity revision ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7jr4-hgqx-vwgq

около 2 лет назад

Access bypass in Drupal core

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
debian логотип
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revision ...

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-7jr4-hgqx-vwgq

Access bypass in Drupal core

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу