MEDIUM5.3
GHSA-mg8j-w93w-xjgc
Drupal Full Path Disclosure
Quick fix
GHSA-mg8j-w93w-xjgc — drupal/drupal: upgrade to the fixed version with the command below.
composer require drupal/drupal:^10.3.6Details
`core/authorize.php` in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of `hash_salt` is `file_get_contents` of a file that does not exist.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/drupal/drupal
Introduced in:
10.3.0Fixed in: 10.3.6Fix
composer require drupal/drupal:^10.3.6Packagist/drupal/drupal
Introduced in:
11.0.0Fixed in: 11.0.5Fix
composer require drupal/drupal:^11.0.5Packagist/drupal/core-recommended
Introduced in:
10.3.0Fixed in: 10.3.6Fix
composer require drupal/core-recommended:^10.3.6Packagist/drupal/core-recommended
Introduced in:
11.0.0Fixed in: 11.0.5Fix
composer require drupal/core-recommended:^11.0.5Packagist/drupal/drupal
Introduced in:
8.0.0Fixed in: 10.2.9Fix
composer require drupal/drupal:^10.2.9Packagist/drupal/core-recommended
Introduced in:
8.0.0Fixed in: 10.2.9Fix
composer require drupal/core-recommended:^10.2.9References
- https://nvd.nist.gov/vuln/detail/CVE-2024-45440[ADVISORY]
- https://github.com/github/advisory-database/pull/4827[WEB]
- https://github.com/drupal/drupal[PACKAGE]
- https://senscybersecurity.nl/CVE-2024-45440-Explained[WEB]
- https://www.drupal.org/project/drupal/issues/3457781[WEB]
- https://www.drupal.org/project/drupal/releases/10.2.9[WEB]
- https://www.drupal.org/project/drupal/releases/10.3.6[WEB]
- https://www.drupal.org/project/drupal/releases/11.0.5[WEB]
- https://www.exploit-db.com/exploits/52266[WEB]