Drupal core - Critical - Cache poisoning - SA-CORE-2023-006
CVE-2023-5256
7.5HIGH
What is CVE-2023-5256?
The JSON:API module in Drupal has a vulnerability that can lead to the exposure of sensitive information through backtraces in error messages. When this module is enabled under certain configurations, it can inadvertently cache error details that are accessible to anonymous users. This poses a risk of privilege escalation, as attackers can gather sensitive data about the site's architecture and potentially exploit it. To protect against this issue, administrators are advised to uninstall the JSON:API module if it is not explicitly needed, as the core REST and contributed GraphQL modules remain unaffected.
Affected Version(s)
Core 10.1 <= 10.1.4
Core 10.0 <= 10.0.11
Core 9.5 <= 9.5.11