[Japanese] | |
JVNDB-2024-000004 | |
Drupal vulnerable to improper handling of structural elements | |
Overview | |
Drupal provided by Drupal.org contains an improper handling of structural elements vulnerability (CWE-237). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 5.3 (Medium) [IPA Score]
CVSS V2 Severity:
Base Metrics 5.0 (Medium) [IPA Score]
| |
Affected Products | |
| |
Drupal | |
The reporter states that Drupal version 9.3.6 was found to be vulnerable to this issue. The developer states that this vulnerability was not reproduced in the version 10 series and the latest version 9.5.x of the version 9 series. | |
Impact | |
An attacker may be able to cause a denial-of-service (DoS) condition. | |
Solution | |
[Update the Software] | |
Vendor Information | |
Drupal | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/01/16 |
Date First Published | 2024/01/16 |
Date Last Updated | 2024/03/12 |