PT-2018-19482 · Packagist · Drupal/Jsonapi
Published
2018-04-25
·
Updated
2018-04-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module provides a JSON API standards-compliant API for accessing and manipulating Drupal content and configuration entities.
The module doesn't provide CSRF protection when processing authenticated traffic using cookie-based authentication.
This vulnerability is mitigated by the fact that an attacker must be allowed to create or modify entities of a certain type, and a very specific and uncommon CORS configuration that allows all other pre-checks to be skipped.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal/Jsonapi