CVE-2024-45440: Medium severity drupal vulnerability
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hashsalt is filegetcontents of a file that does not exist.
Other sources
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hashsalt is filegetcontents of a file that does not exist.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45440?
CVE-2024-45440 is classified as a moderate severity vulnerability.
How do I fix CVE-2024-45440?
To fix CVE-2024-45440, upgrade to Drupal versions 10.2.9, 10.3.6, or 11.0.5 or later.
What does CVE-2024-45440 exploit?
CVE-2024-45440 exploits a Full Path Disclosure vulnerability in core/authorize.php in specific versions of Drupal.
How does CVE-2024-45440 affect Drupal sites?
CVE-2024-45440 can potentially expose sensitive file path information on Drupal sites.
Is CVE-2024-45440 present in Drupal 11.x-dev?
Yes, CVE-2024-45440 is specifically present in Drupal 11.x-dev.