CVE-2024-13254: REST Views - Moderately critical - Information Disclosure - SA-CONTRIB-2024-018
Published Jan 9, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.
Affected Software
2 affected components
Drupal REST Views>0.0.0, <3.0.1
Rest Views Project Rest Views Drupal<3.0.1
Event History
Jan 9, 2025
CVE Published
via MITRE·06:59 PM
Data Sourced
via MITRE·06:59 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13254?
CVE-2024-13254 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-13254?
To fix CVE-2024-13254, upgrade to Drupal REST Views version 3.0.1 or later.
3
What impacts should I be aware of regarding CVE-2024-13254?
CVE-2024-13254 allows for forceful browsing, potentially exposing sensitive information.
4
Which versions of Drupal REST Views are affected by CVE-2024-13254?
CVE-2024-13254 affects versions of Drupal REST Views prior to 3.0.1.
5
Is CVE-2024-13254 related to unauthorized access?
Yes, CVE-2024-13254 can lead to unauthorized access due to the insertion of sensitive information.