SA-CORE-2024-004: Critical severity Drupal Drupal vulnerability
Published Nov 20, 2024
·Updated
Drupal's uniqueness checking for certain user fields is inconsistent depending on the database engine and its collation. As a result, a user may be able to register with the same email address as another user. This may lead to data integrity issues.
Credit
Wayne Eaker
Affected Software
1 affected componentFixes available
Drupal Drupal<10.2.11, <10.3.9, <11.0.8
10.2.1110.3.911.0.8
Event History
Nov 20, 2024
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of SA-CORE-2024-004?
The severity of SA-CORE-2024-004 is critical with a score of 9.
2
How do I fix SA-CORE-2024-004?
To fix SA-CORE-2024-004, ensure that your environment is updated to a version of Drupal that addresses the uniqueness checking issue.
3
What are the impacts of SA-CORE-2024-004?
SA-CORE-2024-004 can lead to data integrity issues by allowing multiple users to register with the same email address.
4
What versions of Drupal are affected by SA-CORE-2024-004?
SA-CORE-2024-004 affects certain versions of Drupal where the database engine's collation and uniqueness checking are inconsistent.
5
When was SA-CORE-2024-004 published?
SA-CORE-2024-004 was published on November 20, 2024.