CVE-2020-13677

HIGH7.5EPSS 0.20%

Drupal core access bypass vulnerability

發布日:2021/9/15修改日:2025/12/10
也稱為:GHSA-3xr3-phjp-g6p2BIT-drupal-2020-13677DRUPAL-CORE-2021-010

描述

Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(4)