CVE-2024-13278: Diff - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-042
Published Jan 9, 2025
·Updated
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
Affected Software
5 affected components
Drupal Diff>0.0.0, <1.8.0
Diff Project Diff Drupal<1.8.0
Diff Project Diff Drupal=2.0.0
Diff Project Diff Drupal=2.0.0-beta1
Diff Project Diff Drupal=2.0.0-beta2
Event History
Jan 9, 2025
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13278?
CVE-2024-13278 is classified as a moderate severity vulnerability affecting Drupal Diff.
2
How do I fix CVE-2024-13278?
To fix CVE-2024-13278, update Drupal Diff to version 1.8.0 or later.
3
What systems are affected by CVE-2024-13278?
CVE-2024-13278 affects Drupal Diff versions from 0.0.0 up to, but not including, 1.8.0.
4
What type of vulnerability is CVE-2024-13278?
CVE-2024-13278 is an Incorrect Authorization vulnerability that can lead to functionality misuse.
5
Is it safe to use Drupal Diff versions lower than 1.8.0 after CVE-2024-13278?
Using Drupal Diff versions lower than 1.8.0 is not safe due to the presence of the Incorrect Authorization vulnerability in CVE-2024-13278.