First published: Thu Jan 09 2025(Updated: )
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Open Social | >=11.8.0<12.3.10>=12.4.0<12.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13312 is classified as a critical vulnerability due to its potential for forceful browsing exploits.
To fix CVE-2024-13312, upgrade your Drupal Open Social installation to version 12.4.9 or later.
CVE-2024-13312 affects Drupal Open Social versions from 11.8.0 up to 12.3.10 and from 12.4.0 up to 12.4.9.
A missing authorization vulnerability like CVE-2024-13312 allows attackers to access restricted resources without proper authentication.
Yes, you can test your site by verifying if it is running an affected version of Drupal Open Social and reviewing access controls.