PT-2024-10129 · Drupal · Drupal Rest Views

·

CVE-2024-13254

·

Published

2024-04-24

·

Updated

2025-01-10

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal REST Views versions 0.0.0 through 3.0.1
Description The issue is related to the insertion of sensitive information into sent data, allowing forceful browsing. This can enable a remote attacker to gain unauthorized access to protected information. The vulnerability is associated with insufficient protection of service data.
Recommendations For versions 0.0.0 through 3.0.1, update to version 3.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST Views module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00386
CVE-2024-13254
DRUPAL-CONTRIB-2024-018

Affected Products

Drupal Rest Views