CVE-2025-3129: Access code - Moderately critical - Access bypass - SA-CONTRIB-2025-028
Published Apr 2, 2025
·Updated
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.
Affected Software
2 affected components
Drupal Access code>0.0.0, <2.0.4
Access Code Project Access Code Drupal<2.0.4
Event History
Apr 2, 2025
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3129?
CVE-2025-3129 is classified as a high severity vulnerability due to its potential for facilitating brute force attacks on authentication.
2
How do I fix CVE-2025-3129?
To fix CVE-2025-3129, upgrade Drupal Access code to version 2.0.4 or later.
3
What impact does CVE-2025-3129 have on my Drupal website?
CVE-2025-3129 can lead to unauthorized access by allowing attackers to continuously attempt authentication until successful.
4
Which versions of Drupal Access code are affected by CVE-2025-3129?
CVE-2025-3129 affects all versions of Drupal Access code from 0.0.0 up to, but not including, 2.0.4.
5
Is there a patch available for CVE-2025-3129?
Yes, a patch is available by upgrading to the recommended version of Drupal Access code.