PT-2020-23075 · Packagist · Drupal Core
Published
2020-06-17
·
Updated
2020-06-17
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
JSON:API PATCH requests may bypass validation for certain fields.
By default, JSON:API works in a read-only mode which makes it impossible to exploit the vulnerability. Only sites that have the
read only set to FALSE under jsonapi.settings config are vulnerable. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal Core