DRUPAL-CONTRIB-2024-005

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2024-005.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-005
Aliases
  • CVE-2024-13241
Withdrawn
2026-03-18T18:00:07.406351Z
Published
2024-01-24T15:47:36Z
Modified
2026-03-18T18:00:07.406351Z
Summary
[none]
Details

Open Social is a Drupal distribution for online communities.

The included optional social_group_flexible_group module doesn't sufficiently validate group updates. The lack of validation makes it possible to have content inside the group changing it's visibility, which could lead to that content being shown to a broader audience than intended.

This vulnerability is mitigated by the fact the module social_group_flexible_group needs to be enabled.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/social

Package

Name
drupal/social
Purl
pkg:composer/drupal/social

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.0.5
Database specific
{
    "constraint": "<12.0.5"
}

Database specific

affected_versions
"<12.0.5"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2024-005.json"