Beveiligingsadvies

CVE-2024-45440

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-08-29 00:00:00
Laatst bijgewerkt 2025-04-21 14:58:52
Toegewezen door drupal
CVSS-score 5.3
Status PUBLISHED

Beschrijving

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.