CVE-2024-13255: RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019
Published Jan 9, 2025
·Updated
Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.
Affected Software
2 affected components
Drupal RESTful Web Services>7.X-2.0, <7.X-2.10
Restful Web Services Project Restful Web Services Drupal>=7.x-2.0<7.x-2.10
Event History
Jan 9, 2025
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13255?
CVE-2024-13255 is considered a medium severity vulnerability due to its potential exposure of sensitive data.
2
How do I fix CVE-2024-13255?
To fix CVE-2024-13255, update the Drupal RESTful Web Services module to version 7.X-2.10 or later.
3
What versions of Drupal are affected by CVE-2024-13255?
CVE-2024-13255 affects Drupal RESTful Web Services versions from 7.X-2.0 to before 7.X-2.10.
4
Can CVE-2024-13255 lead to unauthorized access?
Yes, CVE-2024-13255 can lead to unauthorized access through forceful browsing of sensitive information.
5
Is there a workaround for CVE-2024-13255?
There are no official workarounds for CVE-2024-13255 aside from updating to a secure version.