CVE-2022-25274
Access bypass in Drupal core
5.4
MEDIUM
CVSS 3.1
EPSS 0.42%
描述
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.
如何修補 CVE-2022-25274
要修補 CVE-2022-25274,請將受影響套件升級到下列已修補版本。
- —升級至 9.3.12 或更新版本
- —升級至 9.3.12 或更新版本
- —升級至 9.3.12 或更新版本
CVE-2022-25274 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 9.3.0, < 9.3.12
- >= 9.3.0, < 9.3.12
- >= 9.3.0, < 9.3.12
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |