First published: Mon Mar 31 2025(Updated: )
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing. This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.
Credit: mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal OAuth2 Server | >0.0.0<2.1.0 | |
composer/drupal/oauth2_server | <2.1.0 | 2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31691 is classified as a moderate severity vulnerability due to missing authorization allowing for forceful browsing.
To fix CVE-2025-31691, upgrade the OAuth2 Server to version 2.1.0 or later.
CVE-2025-31691 affects Drupal OAuth2 Server versions from 0.0.0 up to, but not including, 2.1.0.
CVE-2025-31691 can be exploited to execute forceful browsing attacks, allowing unauthorized access to resources.
While CVE-2025-31691 is a specific vulnerability, it highlights the importance of proper authorization mechanisms, relevant to broader security practices within the OAuth2 Server.