Drupal core - Critical - Cache poisoning - SA-CORE-2023-006
CVE-2023-5256
7.5HIGH
Summary
The JSON:API module in Drupal has a vulnerability that can lead to the exposure of sensitive information through backtraces in error messages. When this module is enabled under certain configurations, it can inadvertently cache error details that are accessible to anonymous users. This poses a risk of privilege escalation, as attackers can gather sensitive data about the site's architecture and potentially exploit it. To protect against this issue, administrators are advised to uninstall the JSON:API module if it is not explicitly needed, as the core REST and contributed GraphQL modules remain unaffected.
Affected Version(s)
Core 10.1 <= 10.1.4
Core 10.0 <= 10.0.11
Core 9.5 <= 9.5.11
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved