Drupal core - Critical - Cache poisoning - SA-CORE-2023-006
CVE-2023-5256

7.5HIGH

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
28 September 2023

Summary

The JSON:API module in Drupal has a vulnerability that can lead to the exposure of sensitive information through backtraces in error messages. When this module is enabled under certain configurations, it can inadvertently cache error details that are accessible to anonymous users. This poses a risk of privilege escalation, as attackers can gather sensitive data about the site's architecture and potentially exploit it. To protect against this issue, administrators are advised to uninstall the JSON:API module if it is not explicitly needed, as the core REST and contributed GraphQL modules remain unaffected.

Affected Version(s)

Core 10.1 <= 10.1.4

Core 10.0 <= 10.0.11

Core 9.5 <= 9.5.11

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.