QID 154147

Date Published: 2024-01-25

QID 154147: Drupal Denial of Service (DoS) Vulnerability (CVE-2024-22362)

Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.

Affected version of Drupal is vulnerable to Improper Handling of Structural Elements Leading to Denial of Service (DoS).

Affected versions:
Drupal version 9.3.6

QID Detection Logic (Unauthenticated) :
This QID checks for vulnerable version of Drupal installed on the target.

Successful exploitation of this vulnerability could allow an attacker to cause Denial of Service (DoS) attack by sending specially crafted requests.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade Drupal to latest version for remediating this vulnerability.
    Vendor References

    CVEs related to QID 154147

    Software Advisories
    Advisory ID Software Component Link
    Drupal Releases URL Logo www.drupal.org/project/drupal/releases