Cyber Posture

CVE-2024-13258

Critical

Published: 09 January 2025

Published
09 January 2025
Modified
04 June 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0043 62.6th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.

Security Summary

CVE-2024-13258 is an Incorrect Authorization vulnerability (CWE-863) in the Drupal REST & JSON API Authentication contrib module, which allows forceful browsing past authorization checks. The issue affects all versions of the module from 0.0.0 before 2.0.13. It carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting its critical severity due to network accessibility, low attack complexity, and no requirements for privileges or user interaction.

Remote, unauthenticated attackers can exploit the vulnerability by sending crafted requests to REST and JSON API endpoints, bypassing authorization controls. This enables them to access, modify, or delete sensitive data and resources without permission, resulting in high impacts on confidentiality, integrity, and availability, potentially leading to complete site compromise.

The Drupal security advisory SA-CONTRIB-2024-022, published on 2025-01-09, documents the vulnerability and recommends updating the Drupal REST & JSON API Authentication module to version 2.0.13 or later as the primary mitigation.

Details

CWE(s)
CWE-863

Affected Products

rest \& json api authentication project
rest \& json api authentication
≤ 2.0.13

References