Drupal Full Path Disclosure
Moderate severity
GitHub Reviewed
Published
Aug 29, 2024
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Package
Affected versions
>= 11.0.0, < 11.0.5
>= 10.3.0, < 10.3.6
>= 8.0.0, < 10.2.9
Patched versions
11.0.5
10.3.6
10.2.9
>= 11.0.0, < 11.0.5
>= 10.3.0, < 10.3.6
>= 8.0.0, < 10.2.9
11.0.5
10.3.6
10.2.9
>= 11.0.0, < 11.0.5
>= 10.3.0, < 10.3.6
>= 8.0.0, < 10.2.9
11.0.5
10.3.6
10.2.9
Description
Published by the National Vulnerability Database
Aug 29, 2024
Published to the GitHub Advisory Database
Aug 29, 2024
Reviewed
Aug 29, 2024
Last updated
Oct 29, 2024
core/authorize.php
in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value ofhash_salt
isfile_get_contents
of a file that does not exist.References