CVE-2025-13083

Source
https://cve.org/CVERecord?id=CVE-2025-13083
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13083.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13083
Aliases
Published
2025-11-18T16:55:37.269Z
Modified
2026-07-15T02:13:42.962895601Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
Details

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 before 10.5.6, from 11.0.0 before 11.1.9, from 11.2.0 before 11.2.8, from 7.0 before 7.103.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13083.json",
    "cwe_ids": [
        "CWE-525"
    ],
    "cna_assigner": "drupal"
}
References

Affected packages

Git / git.drupalcode.org/project/drupal

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/drupal
Events
Introduced
35c2f3ca5c935f3d8bde15932a712677c9bbd50f
Fixed
4507fabeab72c8290872f66b1a1a395bd91585ae
Introduced
d4b39f784711f3b861d59c37ec8e9f5592b623ce
Fixed
3f202596d6935bc6915f08b6a1c60e733600d3c1
Introduced
140f94ff1051644c4416c7ed30cc5dd1f14507b2
Fixed
5d83fa7b4b4eda5971085af5d5ff00811016376a
Introduced
338d58439d5b59d92ac9519ad81ffd916b673841
Fixed
f8bdd0862798ad59a8ebf87fb1df69642b799f5a
Introduced
497914920385b7016ac9c9367e0198530787adf2
Last affected
e7242e52bb13286c67d27fad57915f868f50b0a9
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "10.4.9"
        },
        {
            "introduced": "10.5.0"
        },
        {
            "fixed": "10.5.6"
        },
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.1.9"
        },
        {
            "introduced": "11.2.0"
        },
        {
            "fixed": "11.2.8"
        },
        {
            "introduced": "7.0"
        },
        {
            "last_affected": "7.103"
        }
    ]
}
Type
GIT
Repo
https://github.com/drupal/drupal
Events
Database specific
{
    "cpe": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "10.4.9"
        },
        {
            "introduced": "10.5.0"
        },
        {
            "fixed": "10.5.6"
        },
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.1.9"
        },
        {
            "introduced": "11.2.0"
        },
        {
            "fixed": "11.2.8"
        }
    ]
}

Affected versions

10.*
10.0.0-alpha1
10.0.0-alpha3
10.0.0-alpha4
10.0.0-alpha5
10.1.0-alpha1
10.4.0
10.4.0-beta1
10.4.0-rc1
10.4.1
10.4.2
10.4.4
10.4.6
10.4.7
10.4.8
10.5.0
10.5.1
10.5.2
10.5.3
10.5.4
10.5.5
11.*
11.0.0-alpha1
11.1.0
11.1.0-beta1
11.1.0-rc1
11.1.1
11.1.2
11.1.4
11.1.6
11.1.7
11.1.8
11.2.0
11.2.1
11.2.2
11.2.3
11.2.4
11.2.5
11.2.6
11.2.7
7.*
7.0
7.10
7.100
7.101
7.103
7.12
7.14
7.15
7.17
7.22
7.23
7.25
7.28
7.30
7.33
7.36
7.37
7.4
7.40
7.42
7.43
7.50
7.51
7.54
7.55
7.56
7.6
7.61
7.64
7.68
7.7
7.71
7.76
7.77
7.79
7.8
7.81
7.83
7.84
7.85
7.87
7.89
7.9
7.90
7.92
7.93
7.94
7.97
7.98
7.99
8.*
8.0.0
8.1.0-beta1
9.*
9.0.0-alpha1
9.0.0-alpha2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13083.json"