Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-25274

Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.3%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2022-25274
  • Drupal » Drupal » Version: 9.3.0
    cpe:2.3:a:drupal:drupal:9.3.0
  • Drupal » Drupal » Version: 9.3.1
    cpe:2.3:a:drupal:drupal:9.3.1
  • Drupal » Drupal » Version: 9.3.10
    cpe:2.3:a:drupal:drupal:9.3.10
  • Drupal » Drupal » Version: 9.3.11
    cpe:2.3:a:drupal:drupal:9.3.11
  • Drupal » Drupal » Version: 9.3.2
    cpe:2.3:a:drupal:drupal:9.3.2
  • Drupal » Drupal » Version: 9.3.3
    cpe:2.3:a:drupal:drupal:9.3.3
  • Drupal » Drupal » Version: 9.3.4
    cpe:2.3:a:drupal:drupal:9.3.4
  • Drupal » Drupal » Version: 9.3.5
    cpe:2.3:a:drupal:drupal:9.3.5
  • Drupal » Drupal » Version: 9.3.6
    cpe:2.3:a:drupal:drupal:9.3.6
  • Drupal » Drupal » Version: 9.3.7
    cpe:2.3:a:drupal:drupal:9.3.7
  • Drupal » Drupal » Version: 9.3.8
    cpe:2.3:a:drupal:drupal:9.3.8
  • Drupal » Drupal » Version: 9.3.9
    cpe:2.3:a:drupal:drupal:9.3.9


Contact Us

Shodan ® - All rights reserved