—
DRUPAL-CONTRIB-2025-019
Details
The Cache Utility module provides an ability to view status and flush various caches.
The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when flushing a cache.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/cache_utility
Introduced in:
0Fixed in: 1.2.1Upgrade drupal/cache_utility to 1.2.1 or newer (ecosystem packagist:https://packages.drupal.org/8).