CVE-2024-13269: Advanced Varnish - Moderately critical - Access bypass - SA-CONTRIB-2024-033
Published Jan 9, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.
Affected Software
2 affected components
Drupal Advanced Varnish>=0.0.0, <4.0.11
Advanced Varnish Project Advanced Varnish Drupal<4.0.11
Event History
Jan 9, 2025
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13269?
CVE-2024-13269 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-13269?
To fix CVE-2024-13269, upgrade your Drupal Advanced Varnish to version 4.0.11 or later.
3
What versions are affected by CVE-2024-13269?
CVE-2024-13269 affects Drupal Advanced Varnish versions from 0.0.0 up to, but not including, 4.0.11.
4
What type of vulnerability is CVE-2024-13269?
CVE-2024-13269 is an insertion of sensitive information into sent data vulnerability.
5
What software does CVE-2024-13269 impact?
CVE-2024-13269 impacts the Advanced Varnish module in Drupal.