Access Bypass Vulnerability in Drupal Core by Drupal
CVE-2020-13665
What is CVE-2020-13665?
An access bypass vulnerability in Drupal Core exists when JSON:API operates in read/write mode without appropriate configurations. Specifically, only sites with the 'read_only' setting configured to FALSE under jsonapi.settings are at risk. This flaw allows unauthorized access to certain API resources, potentially exposing sensitive data. It affects multiple versions of Drupal Core, necessitating updates to ensure the security and integrity of web applications running on this platform.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Drupal Core 8.8.x < 8.8.8
Drupal Core 8.9.x < 8.9.1
Drupal Core 9.0.x < 9.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
