CVE-2013-1946: Input Validation
The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1946?
CVE-2013-1946 has a medium severity rating as it can lead to denial of service attacks.
How do I fix CVE-2013-1946?
To fix CVE-2013-1946, update the Restful Web Services module to version 7.x-1.3 or 7.x-2.0-alpha5 or later.
What versions of Restful Web Services are affected by CVE-2013-1946?
CVE-2013-1946 affects versions 7.x-1.1 and 7.x-1.2 as well as 7.x-2.0-alpha3 and 7.x-2.0-alpha4.
Who can exploit CVE-2013-1946?
CVE-2013-1946 can be exploited by remote attackers, especially when page caching is enabled and anonymous users have RESTWS permissions.
What impact does CVE-2013-1946 have on users?
The impact of CVE-2013-1946 can cause service disruption for users by enabling denial of service through crafted HTTP requests.