CVE-2025-13083: Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8.
Other sources
Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13083?
CVE-2025-13083 is classified as a moderate severity vulnerability affecting Drupal core.
How do I fix CVE-2025-13083?
To fix CVE-2025-13083, update Drupal core to version 10.5.6 or higher, or 11.1.9 or higher.
What versions of Drupal are affected by CVE-2025-13083?
CVE-2025-13083 affects Drupal core versions from 8.0.0 before 10.4.9, and from 10.5.0 before 10.5.6 and from 11.0.0 before 11.1.9.
What type of vulnerability is CVE-2025-13083?
CVE-2025-13083 is a use of web browser cache containing sensitive information vulnerability.
What can happen if CVE-2025-13083 is exploited?
Exploitation of CVE-2025-13083 can lead to incorrect access control and exposure of sensitive information stored in the web browser cache.