DRUPAL-CONTRIB-2025-019

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/cache_utility/DRUPAL-CONTRIB-2025-019.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2025-019
Aliases
Published
2025-02-26T18:35:11Z
Modified
2026-09-10T03:45:35Z
Summary
[none]
Details

The Cache Utility module provides an ability to view status and flush various caches.

The module doesn't sufficiently protect against Cross Site Request Forgery (CSRF) attacks by validating user identity and intent when flushing a cache.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/cache_utility

Package

Name
drupal/cache_utility
Purl
pkg:composer/drupal/cache_utility?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.1
Database specific
Show details
{
    "constraint": "<1.2.1"
}

Database specific

affected_versions
"<1.2.1"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/cache_utility/DRUPAL-CONTRIB-2025-019.json"