Логотип exploitDog
bind:CVE-2022-25274
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25274

Количество 4

Количество 4

ubuntu логотип

CVE-2022-25274

больше 2 лет назад

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-25274

больше 2 лет назад

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-25274

больше 2 лет назад

Drupal 9.3 implemented a generic entity access API for entity revision ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7jr4-hgqx-vwgq

больше 2 лет назад

Access bypass in Drupal core

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revision ...

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7jr4-hgqx-vwgq

Access bypass in Drupal core

CVSS3: 5.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу