CVE-2024-13258: Drupal REST & JSON API Authentication - Moderately critical - Access bypass - SA-CONTRIB-2024-022
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13258?
CVE-2024-13258 is classified as a medium severity vulnerability affecting Drupal REST & JSON API Authentication.
How do I fix CVE-2024-13258?
To fix CVE-2024-13258, update your Drupal REST & JSON API Authentication to version 2.0.14 or later.
What types of attacks can exploit CVE-2024-13258?
CVE-2024-13258 can be exploited through forceful browsing attacks that bypass authorization controls.
Which versions of Drupal are impacted by CVE-2024-13258?
CVE-2024-13258 affects all versions of Drupal REST & JSON API Authentication from 0.0.0 up to and including 2.0.13.
Is there a workaround for CVE-2024-13258 if I cannot apply the update?
Currently, the best mitigation for CVE-2024-13258 is to restrict access to the affected API endpoints until an update can be applied.