CVE-2023-5256

CVE-2023-5256: Drupal core - Critical - Cache poisoning - SA-CORE-2023-006

Vendor Drupal
Product Core
Weakness CWE-200 · Info exposure
Published September 28, 2023
Last update September 23, 2024

CVSS base score

What the vulnerability does

Description

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API. The core REST and contributed GraphQL modules are not affected.

Key dates

Disclosure timeline

September 28, 2023 CVE published
September 23, 2024 Record updated