CVE-2024-13249: Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013
Published Jan 9, 2025
·Updated
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.
Affected Software
2 affected components
Drupal Node Access Rebuild Progressive>7.X-1.0, <7.X-1.2
Node Access Rebuild Progressive Project Node Access Rebuild Progressive Drupal>=7.x-1.0<7.x-1.2
Event History
Jan 9, 2025
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13249?
CVE-2024-13249 is classified as a moderate severity vulnerability affecting Drupal Node Access Rebuild Progressive.
2
How do I fix CVE-2024-13249?
To fix CVE-2024-13249, update Drupal Node Access Rebuild Progressive to version 7.X-1.2 or later.
3
Who is affected by CVE-2024-13249?
Users of Drupal Node Access Rebuild Progressive versions 7.X-1.0 to 7.X-1.2 are affected by CVE-2024-13249.
4
What does CVE-2024-13249 exploit?
CVE-2024-13249 exploits improper ownership management, potentially allowing unauthorized access to node content.
5
Is there a workaround for CVE-2024-13249?
There are no known workarounds for CVE-2024-13249; the best solution is to apply the necessary update.