CVE-2020-13676 – drupal/core
Package
Manager: composer
Name: drupal/core
Vulnerable Version: >=8.0.0 <8.9.19 || >=9.1.0 <9.1.13 || >=9.2.0 <9.2.6
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00215 pctl0.44024
Details
Incorrect Authorization in Drupal core The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
Metadata
Created: 2022-02-12T00:00:46Z
Modified: 2022-02-23T16:04:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-qfhg-m6r8-xxpj/GHSA-qfhg-m6r8-xxpj.json
CWE IDs: ["CWE-284", "CWE-863"]
Alternative ID: GHSA-qfhg-m6r8-xxpj
Finding: F039
Auto approve: 1