CVE-2024-13246: Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010
Published Jan 9, 2025
·Updated
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.
Affected Software
2 affected components
Drupal Node Access Rebuild Progressive<2.0.2
Node Access Rebuild Progressive Project Node Access Rebuild Progressive Drupal<2.0.2
Event History
Jan 9, 2025
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13246?
CVE-2024-13246 has a moderate severity rating due to its potential for Target Influence via Framing.
2
How do I fix CVE-2024-13246?
To fix CVE-2024-13246, upgrade to Node Access Rebuild Progressive version 2.0.2 or later.
3
Which software versions are affected by CVE-2024-13246?
CVE-2024-13246 affects all versions of Node Access Rebuild Progressive prior to 2.0.2.
4
What is the impact of CVE-2024-13246?
The impact of CVE-2024-13246 allows unauthorized access and manipulation of node permissions through improper ownership management.
5
Is there a patch available for CVE-2024-13246?
Yes, a patch is available in the form of an upgrade to version 2.0.2 of Node Access Rebuild Progressive.