Web Browser Cache Vulnerability in Drupal Core Affects Multiple Versions
CVE-2025-13083
Currently unrated
What is CVE-2025-13083?
A vulnerability exists in Drupal core that enables exploitation through incorrectly configured access control security levels. This issue allows unauthorized access to sensitive information cached in web browsers, potentially exposing data to malicious users. Drupal versions impacted include releases from 8.0.0 up to 10.4.9, from 10.5.0 to 10.5.6, from 11.0.0 to 11.1.9, and from 11.2.0 to 11.2.8. Webmasters and administrators should ensure proper configuration of access security settings to mitigate risks associated with this vulnerability.
Affected Version(s)
Drupal core 8.0.0 < 10.4.9
Drupal core 10.5.0 < 10.5.6
Drupal core 11.0.0 < 11.1.9
References
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Damien McKenna (damienmckenna)
tame4tex
Benji Fisher (benjifisher)
catch (catch)
Neil Drumm (drumm)
Lee Rowlands (larowlan)
Mingsong (mingsong)
Mohit Aghera (mohit_aghera)
James Gilliland (neclimdul)
Juraj Nemec (poker10)
Jess (xjm)
catch (catch)
Lee Rowlands (larowlan)
Dave Long (longwave)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
