Improper Condition Check in Drupal's HTTP Client Manager Affects Multiple Versions
CVE-2025-14840
7.5HIGH
What is CVE-2025-14840?
A vulnerability in the HTTP Client Manager of Drupal has been identified, which permits unauthorized access through forceful browsing. This issue is linked to improper checks for unusual conditions in the application's security framework, potentially allowing attackers to navigate to restricted resources without proper authentication. It affects several versions of the HTTP Client Manager, leaving users susceptible to security breaches. Timely updates are essential to safeguard against potential exploitation.
Affected Version(s)
HTTP Client Manager 0.0.0 < 9.3.13
HTTP Client Manager 10.0.0 < 10.0.2
HTTP Client Manager 11.0.0 < 11.0.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mxh
Adriano Cori (aronne)
mxh
Greg Knaddison (greggles)
Juraj Nemec (poker10)
