CVE-2023-5256

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.

This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API.

The core REST and contributed GraphQL modules are not affected.



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 50.54%
Affected Products (NVD)
VendorProductVersion
drupaldrupal
8.7.0 ≤
𝑥
< 9.5.11
drupaldrupal
10.0.0 ≤
𝑥
< 10.0.11
drupaldrupal
10.1.0 ≤
𝑥
< 10.1.4
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
drupaldrupal
10.1 ≤
𝑥
< 10.1.4
ADP
drupaldrupal
10.0 ≤
𝑥
< 10.0.11
ADP
drupaldrupal
9.5 ≤
𝑥
< 9.5.11
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
drupal7
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
ignored