Drupal Security Update – 19 May 2024

Drupal has released a security update to fix a vulnerability in Drupal’s RESTful Web Services.

The addressed vulnerability could allow the remote attacker to bypass security restrictions by sending a specially crafted request to the affected products.

Drupal RESTful Web Services Access Bypass (SA-CONTRIB-2024-019):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: None
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security

Affected products:

  • Drupal RESTful Web Services Module for Drupal 7.x-2.7
  • Drupal RESTful Web Services Module for Drupal 7.x-2.9
  • Drupal RESTful Web Services Module for Drupal 7.x-2.8
Vulnerabilities

SA-CONTRIB-2024-019

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Drupal Security Advisory

References