PT-2022-8504 · Drupal · Drupal Core Json:Api Module

Brad Jones

·

Published

2022-02-11

·

Updated

2024-03-06

·

CVE-2020-13677

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal core JSON:API module (affected versions not specified)
Description The issue arises when the Drupal core JSON:API module fails to properly restrict access to certain content under specific circumstances, potentially leading to unintended access bypass. It is noted that sites without the JSON:API module enabled are not affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-DRUPAL-2020-13677
CVE-2020-13677
DRUPAL-CORE-2021-010
GHSA-3XR3-PHJP-G6P2

Affected Products

Drupal Core Json:Api Module