First published: Thu Jan 09 2025(Updated: )
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Views | >0.0.0<3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13254 has been classified as a moderate severity vulnerability.
To fix CVE-2024-13254, upgrade to Drupal REST Views version 3.0.1 or later.
CVE-2024-13254 allows for forceful browsing, potentially exposing sensitive information.
CVE-2024-13254 affects versions of Drupal REST Views prior to 3.0.1.
Yes, CVE-2024-13254 can lead to unauthorized access due to the insertion of sensitive information.