nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13246 CVE-2024-13246
MEDIUM
Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010
Record summary
CVE-2024-13246 has a selected CVSS score of 5.3 (medium).
Description
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Node Access Rebuild ProgressiveBrowse Drupal / Node Access Rebuild ProgressiveDefault status: unaffected | CVE List | 0.0.0 to < 2.0.2 | affected |
References
2drupal.org
https://www.drupal.org/sa-contrib-2024-010