DRUPAL-CONTRIB-2024-008

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/migrate_tools/DRUPAL-CONTRIB-2024-008.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-008
Aliases
  • CVE-2024-13244
Published
2024-02-07T17:56:55Z
Modified
2025-12-10T23:41:30.443267Z
Summary
[none]
Details

The Migrate Tools module provides tools for running and managing Drupal migrations.

The module doesn't sufficiently protect against Cross Site Request Forgery under specific scenarios allowing an attacker to trick an authenticated administrator into initiating a migration.

This vulnerability is mitigated by the fact that an attacker must know the name of the migration.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/migrate_tools

Package

Name
drupal/migrate_tools
Purl
pkg:composer/drupal/migrate_tools

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.3
Database specific
{
    "constraint": "<6.0.3"
}

Database specific

affected_versions
"<6.0.3"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/migrate_tools/DRUPAL-CONTRIB-2024-008.json"