CVE-2023-5256: Drupal core - Critical - Cache poisoning - SA-CORE-2023-006
In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.
This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API.
The core REST and contributed GraphQL modules are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Drupal vulnerability?
The vulnerability ID of this Drupal vulnerability is CVE-2023-5256.
What is the severity of CVE-2023-5256?
The severity of CVE-2023-5256 is high.
Which Drupal module is affected by CVE-2023-5256?
The JSON:API module of Drupal is affected by CVE-2023-5256.
Which versions of Drupal are affected by CVE-2023-5256?
Drupal versions 8.7.0 to 9.5.11 and Drupal versions 10.0.0 to 10.0.11 are affected by CVE-2023-5256.
What is the risk of CVE-2023-5256?
CVE-2023-5256 may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.