CVE-2024-13272: Paragraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-036
Published Jan 9, 2025
·Updated
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.
Affected Software
3 affected components
Drupal Paragraphs<1.23.0, <2.0.2
Paragraphs Table Project Paragraphs Table Drupal<1.23
Paragraphs Table Project Paragraphs Table Drupal>=2.0.0<2.0.2
Event History
Jan 9, 2025
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13272?
CVE-2024-13272 has a medium severity rating due to its potential for content spoofing.
2
How do I fix CVE-2024-13272?
To fix CVE-2024-13272, update Drupal Paragraphs to version 1.23.0 or 2.0.2 or later.
3
What is the impact of CVE-2024-13272?
The impact of CVE-2024-13272 allows attackers to spoof content by exploiting insufficient access control in the Paragraphs table.
4
Which versions of Drupal Paragraphs are affected by CVE-2024-13272?
CVE-2024-13272 affects Drupal Paragraphs versions before 1.23.0 and versions from 2.0.0 before 2.0.2.
5
Is there a workaround for CVE-2024-13272 if I cannot update immediately?
There are no official workarounds for CVE-2024-13272, so it is recommended to prioritize the update.