First published: Fri Feb 11 2022(Updated: )
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
Credit: mlhess@drupal.org mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=9.2.0<9.2.6 | 9.2.6 |
composer/drupal/core | >=9.1.0<9.1.13 | 9.1.13 |
composer/drupal/core | >=8.0.0<8.9.19 | 8.9.19 |
Drupal Drupal | >=8.0.0<8.9.19 | |
Drupal Drupal | >=9.1.0<9.1.13 | |
Drupal Drupal | >=9.2.0<9.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13677 is a vulnerability in the Drupal core JSON:API module that can result in unintended access bypass.
Sites that have the Drupal core JSON:API module enabled and are running versions between 8.0.0 and 8.9.19, 9.1.0 and 9.1.13, or 9.2.0 and 9.2.6 are affected.
CVE-2020-13677 has a severity rating of 7.5, which is considered high.
To fix CVE-2020-13677, Drupal site owners should update the JSON:API module to version 8.9.19, 9.1.13, or 9.2.6, depending on the version being used.
You can find more information about CVE-2020-13677 on the National Vulnerability Database (NVD), Drupal's security advisory, and the GitHub commit.