CVE-2025-31691: OAuth2 Server - Moderately critical - Access bypass - SA-CONTRIB-2025-020
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing. This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.
Other sources
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31691?
CVE-2025-31691 is classified as a moderate severity vulnerability due to missing authorization allowing for forceful browsing.
How do I fix CVE-2025-31691?
To fix CVE-2025-31691, upgrade the OAuth2 Server to version 2.1.0 or later.
Which versions of Drupal OAuth2 Server are affected by CVE-2025-31691?
CVE-2025-31691 affects Drupal OAuth2 Server versions from 0.0.0 up to, but not including, 2.1.0.
What type of attack can be executed due to CVE-2025-31691?
CVE-2025-31691 can be exploited to execute forceful browsing attacks, allowing unauthorized access to resources.
Is CVE-2025-31691 related to other vulnerabilities in the OAuth2 Server?
While CVE-2025-31691 is a specific vulnerability, it highlights the importance of proper authorization mechanisms, relevant to broader security practices within the OAuth2 Server.