nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13249 CVE-2024-13249
MEDIUM
Node Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-013
Record summary
CVE-2024-13249 has a selected CVSS score of 5.4 (medium).
Description
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Node Access Rebuild ProgressiveBrowse Drupal / Node Access Rebuild ProgressiveDefault status: unaffected | CVE List | 7.x-1.0 to < 7.x-1.2 | affected |
References
2drupal.org
https://www.drupal.org/sa-contrib-2024-013