Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918704 (CVE-2023-5256, SA-CORE-2023-006) - <www-apps/drupal-{9.5.11,10.0.11}: information leakage via error backtraces
Summary: <www-apps/drupal-{9.5.11,10.0.11}: information leakage via error backtraces
Status: RESOLVED FIXED
Alias: CVE-2023-5256, SA-CORE-2023-006
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://www.drupal.org/sa-core-2023-006
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-28 19:23 UTC by John Helmert III
Modified: 2023-11-28 19:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-28 19:23:13 UTC
CVE-2023-5256:

In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation.

This vulnerability only affects sites with the JSON:API module enabled, and can be mitigated by uninstalling JSON:API.

The core REST and contributed GraphQL modules are not affected.

7.x is unaffected, 9.5 is fixed with 9.5.11 and 10.0 is fixed with 10.0.11, all done!