PT-2024-10354 · Drupal · Node Access Rebuild Progressive
Damien Mckenna
+3
·
Published
2024-02-21
·
Updated
2025-01-10
·
CVE-2024-13246
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Node Access Rebuild Progressive versions 0.0.0 through 2.0.1
Node Access Rebuild Progressive version prior to 2.0.2 can be simplified to the above range, so it is omitted to avoid duplication.
Description
The issue is related to improper ownership management in the Node Access Rebuild Progressive module of the Drupal CMS system, which is associated with access control deficiencies. This can allow a remote attacker to bypass security restrictions. The vulnerability may enable an attacker to influence the target via framing.
Recommendations
For Node Access Rebuild Progressive versions 0.0.0 through 2.0.1, update to version 2.0.2 or later to resolve the issue.
At the moment, there is no other information about additional mitigation measures for this vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node Access Rebuild Progressive