CVE-2020-13675

Name
CVE-2020-13675
Description
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://www.drupal.org/sa-core-2021-008

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* drupal >= 8.0.0 < 8.9.19
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* drupal >= 9.1.0 < 9.1.13
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* drupal >= 9.2.0 < 9.2.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status