CVE-2024-55634: Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
Other sources
Drupal's uniqueness checking for certain user fields is inconsistent depending on the database engine and its collation. As a result, a user may be able to register with the same email address as another user. This may lead to data integrity issues. This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55634?
The severity of CVE-2024-55634 is classified as a Privilege Escalation vulnerability.
How do I fix CVE-2024-55634?
To fix CVE-2024-55634, update Drupal Core to version 11.0.8, 10.3.9, or 10.2.11.
What versions are affected by CVE-2024-55634?
CVE-2024-55634 affects Drupal Core versions from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, and from 11.0.0 before 11.0.8.
What type of vulnerability is CVE-2024-55634?
CVE-2024-55634 is a Privilege Escalation vulnerability in Drupal Core.
Is CVE-2024-55634 being actively exploited?
There is no public information indicating that CVE-2024-55634 is currently being actively exploited.