QID 730199
Date Published: 2021-09-20
QID 730199: Drupal Core Access Bypass Vulnerability (SA-CORE-2021-010)
Drupal is a free and open source content management framework written in PHP and distributed under the GNU General Public License.
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass.
Affected Versions:
Drupal 8.9.x, prior to Drupal 8.9.19.
Drupal 9.1.x, prior to Drupal 9.1.13.
Drupal 9.2.x, prior to Drupal 9.2.6.
QID Detection Logic:
This QID checks for vulnerable version of Drupal installed on the target via a version based check.
Successful exploitation of the vulnerability may allow an attacker to bypass access and view sensitive files on the webserver
Workaround:
Sites that do not have the JSON:API module enabled are not affected.
- SA-CORE-2021-010 -
www.drupal.org/sa-core-2021-010
CVEs related to QID 730199
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SA-CORE-2021-010 |
|