CVE-2024-45440

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.
Configurations

Configuration 1 (hide)

cpe:2.3:a:drupal:drupal:2023-05-09:*:*:*:*:*:*:*

History

19 Sep 2024, 17:38

Type Values Removed Values Added
CWE CWE-209
First Time Drupal
Drupal drupal
CPE cpe:2.3:a:drupal:drupal:2023-05-09:*:*:*:*:*:*:*
References () https://senscybersecurity.nl/CVE-2024-45440-Explained/ - () https://senscybersecurity.nl/CVE-2024-45440-Explained/ - Third Party Advisory
References () https://www.drupal.org/project/drupal/issues/3457781 - () https://www.drupal.org/project/drupal/issues/3457781 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

12 Sep 2024, 16:15

Type Values Removed Values Added
References () https://senscybersecurity.nl/CVE-2024-45440-Explained/ - () https://senscybersecurity.nl/CVE-2024-45440-Explained/ -
References () https://www.drupal.org/project/drupal/issues/3457781 - () https://www.drupal.org/project/drupal/issues/3457781 -

03 Sep 2024, 18:15

Type Values Removed Values Added
References
  • () https://senscybersecurity.nl/CVE-2024-45440-Explained/ -
Summary
  • (es) core/authorize.php en Drupal 11.x-dev permite la divulgación de ruta completa (incluso cuando el registro de errores es Ninguno) si el valor de hash_salt es file_get_contents de un archivo que no existe.

29 Aug 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-29 11:15

Updated : 2024-09-19 17:38


NVD link : CVE-2024-45440

Mitre link : CVE-2024-45440

CVE.ORG link : CVE-2024-45440


JSON object : View

Products Affected

drupal

  • drupal
CWE
CWE-209

Generation of Error Message Containing Sensitive Information