First published: Thu Aug 29 2024(Updated: )
`core/authorize.php` in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of `hash_salt` is `file_get_contents` of a file that does not exist.
Credit: cve@mitre.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =2023-05-09 | |
composer/drupal/core | >=8.0.0<10.2.9 | 10.2.9 |
composer/drupal/core-recommended | >=8.0.0<10.2.9 | 10.2.9 |
composer/drupal/drupal | >=8.0.0<10.2.9 | 10.2.9 |
composer/drupal/core | >=10.3.0<10.3.6 | 10.3.6 |
composer/drupal/core-recommended | >=10.3.0<10.3.6 | 10.3.6 |
composer/drupal/drupal | >=10.3.0<10.3.6 | 10.3.6 |
composer/drupal/core | >=11.0.0<11.0.5 | 11.0.5 |
composer/drupal/core-recommended | >=11.0.0<11.0.5 | 11.0.5 |
composer/drupal/drupal | >=11.0.0<11.0.5 | 11.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.