PT-2020-23075 · Packagist · Drupal Core

Published

2020-06-17

·

Updated

2020-06-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
JSON:API PATCH requests may bypass validation for certain fields.
By default, JSON:API works in a read-only mode which makes it impossible to exploit the vulnerability. Only sites that have the read only set to FALSE under jsonapi.settings config are vulnerable.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CORE-2020-006

Affected Products

Drupal Core