PT-2026-66339 · Drupal+2 · Token Content Access+2
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Token Content Access versions 0.0.0 through 3.1.2
Description
An observable timing discrepancy exists in the Token Content Access module, which allows site administrators to grant content access via access tokens. The module fails to sufficiently protect the comparison of access tokens, enabling a persistent attacker to perform a timing attack—a method of guessing secret data by measuring how long a system takes to respond—to discover a valid token and bypass access restrictions. Exploitation requires the attacker to know the URL of the protected content and accurately measure timing differences in the responses.
Recommendations
Update Token Content Access to a version later than 3.1.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Token Content Access
Drupal/Tca
Tca