CVE-2013-1946

EUVD-2013-1938
The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
restful_web_services_projectrestful_web_services
7.x-1.1:x
restful_web_services_projectrestful_web_services
7.x-1.2:x
restful_web_services_projectrestful_web_services
7.x-2.0:x
restful_web_services_projectrestful_web_services
7.x-2.0:x
𝑥
= Vulnerable software versions