Project:
Date:
2024-May-15
Vulnerability:
Access bypass
CVE IDs:
CVE-2024-13255
Description:
This module exposes Drupal resources (e.g. entities) as RESTful web services.
The module doesn't sufficiently restrict access for user resources.
Solution:
Install the latest version:
- If you use the RESTful Web Services module for Drupal 7, upgrade to RESTful Web Services 7.x-2.10
Reported By:
Fixed By:
- Neil Drumm of the Drupal Security Team
- Fran Garcia-Linares
Coordinated By:
- Neil Drumm of the Drupal Security Team