Record summary

CVE-2020-13675 has a selected CVSS score of 9.8 (critical).

Description

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List9.2.x to < 9.2.6affected
9.1.x to < 9.1.13affected
8.9.x to < 8.9.19affected
GitHub Advisory8.0.0 to < 8.9.19 · Fixed in 8.9.19affected
9.1.0 to < 9.1.13 · Fixed in 9.1.13affected
9.2.0 to < 9.2.6 · Fixed in 9.2.6affected

References

3