Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sergii Bondarenko

#24425of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2020-6400
9.8
2020-06-10
Drupal · Drupal Core · CVE-2020-13665
**Name of the Vulnerable Software and Affected Versions** Drupal Core versions prior to 8.8.8 Drupal Core versions prior to 8.9.1 Drupal Core versions prior to 9.0.1 **Description** The issue is related to improper authorization in the Drupal Core JSON:API module when the read only setting is set to FALSE. This can allow a remote attacker to access sensitive data, compromise data integrity, and potentially cause a denial of service. The vulnerability affects sites with JSON:API in read/write mode. **Recommendations** For versions prior to 8.8.8, update to version 8.8.8 or later. For versions prior to 8.9.1, update to version 8.9.1 or later. For versions prior to 9.0.1, update to version 9.0.1 or later. As a temporary workaround, consider setting the read only setting to TRUE under jsonapi.settings config to prevent exploitation.