First published: Mon Mar 31 2025(Updated: )
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing. This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open Social | >0.0.0<12.3.11>12.4.0<12.4.10 | |
composer/goalgorilla/open_social | >=12.4.0<12.4.10 | 12.4.10 |
composer/goalgorilla/open_social | <12.3.11 | 12.3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31685 is classified as a moderate severity vulnerability due to the risk of forceful browsing.
To fix CVE-2025-31685, you should upgrade your Drupal Open Social installation to version 12.4.10 or later.
CVE-2025-31685 affects Open Social versions from 0.0.0 to before 12.3.11 and from 12.4.0 to before 12.4.10.
The missing authorization in CVE-2025-31685 allows unauthorized users to access resources they shouldn't have permission to view.
Yes, a patch is included in the updates for Drupal Open Social version 12.4.10 and later.