Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Solideogloria

#22331of 53,624
10Total CVSS
Vulnerabilities · 1
PT-2024-10094
10
2024-05-29
Drupal · Drupal Rest & Json Api Authentication · CVE-2024-13258
**Name of the Vulnerable Software and Affected Versions** Drupal REST & JSON API Authentication versions 0.0.0 through 2.0.12 **Description** The issue is related to an Incorrect Authorization vulnerability in Drupal REST & JSON API Authentication, allowing Forceful Browsing. This can enable a remote attacker to bypass existing security restrictions. **Recommendations** For versions 0.0.0 through 2.0.12, update to version 2.0.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST & JSON API Authentication module until a patch is applied.