QID 996393

Date Published: 2023-12-21

QID 996393: PHP (Composer) Security Update for drupal/core (GHSA-rjqg-3h9m-fx5x)

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Github security advisory GHSA-rjqg-3h9m-fx5x for updates and patch information.
    Vendor References

    CVEs related to QID 996393

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rjqg-3h9m-fx5x drupal/core URL Logo github.com/advisories/GHSA-rjqg-3h9m-fx5x