PT-2025-2091 · Drupal · Drupal Security Kit

B0Lli

+4

·

Published

2024-09-11

·

Updated

2025-01-14

·

CVE-2024-13275

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Drupal Security Kit versions 0.0.0 through 2.0.2
Description The issue is related to a 'Type Confusion' vulnerability, which allows an attacker to cause a denial of service via HTTP. This vulnerability can be exploited by a remote attacker.
Recommendations For versions 0.0.0 through 2.0.2, update to version 2.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to resources that may be affected by the 'Type Confusion' vulnerability until a patch is available.

Fix

DoS

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-01219
CVE-2024-13275
DRUPAL-CONTRIB-2024-039

Affected Products

Drupal Security Kit