PT-2025-2093 · Drupal · Diff

Adam Bramley

+4

·

Published

2024-10-02

·

Updated

2025-01-10

·

CVE-2024-13278

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Diff versions 0.0.0 through 1.8.0
Description The issue is related to an incorrect authorization vulnerability in the Diff module of the Drupal content management system. This vulnerability allows for functionality misuse. A remote attacker may exploit this issue to gain access to confidential information.
Recommendations For versions 0.0.0 through 1.8.0, update to version 1.8.0 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-01112
CVE-2024-13278
DRUPAL-CONTRIB-2024-042

Affected Products

Diff