CVE-2024-13312

Source
https://cve.org/CVERecord?id=CVE-2024-13312
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-13312.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-13312
Published
2025-01-09T20:28:53.431Z
Modified
2026-07-15T01:49:06.298494657Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076
Details

Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/13xxx/CVE-2024-13312.json",
    "cwe_ids": [
        "CWE-862"
    ],
    "cna_assigner": "drupal"
}
References

Affected packages

Git / git.drupalcode.org/project/social

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/social
Events
Introduced
f8f9adbd4d5c7667626af917ffe7e9e915825dbd
Fixed
462040351f86563f953a875b55c3cfe7a3cf8c53
Introduced
322fa126ac73a47cc5b228dc94d944b847c93d84
Fixed
ff6c77fa34dfc2e5e76a020063ee794ea980df3a
Database specific
{
    "extracted_events": [
        {
            "introduced": "11.8.0"
        },
        {
            "fixed": "12.3.10"
        },
        {
            "introduced": "12.4.0"
        },
        {
            "fixed": "12.4.9"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

12.*
12.4.0
12.4.1
12.4.2
12.4.3
12.4.4
12.4.5
12.4.6
12.4.7
12.4.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-13312.json"