PT-2020-6400 · Drupal · Drupal Core

Sergii Bondarenko

·

Published

2020-06-10

·

Updated

2024-03-06

·

CVE-2020-13665

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drupal Core versions prior to 8.8.8 Drupal Core versions prior to 8.9.1 Drupal Core versions prior to 9.0.1
Description The issue is related to improper authorization in the Drupal Core JSON:API module when the read only setting is set to FALSE. This can allow a remote attacker to access sensitive data, compromise data integrity, and potentially cause a denial of service. The vulnerability affects sites with JSON:API in read/write mode.
Recommendations For versions prior to 8.8.8, update to version 8.8.8 or later. For versions prior to 8.9.1, update to version 8.9.1 or later. For versions prior to 9.0.1, update to version 9.0.1 or later. As a temporary workaround, consider setting the read only setting to TRUE under jsonapi.settings config to prevent exploitation.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-04620
BIT-DRUPAL-2020-13665
CVE-2020-13665
GHSA-WXQP-JWC9-G39X

Affected Products

Drupal Core