VDB
CVE-2020-13675
CVE-2020-13675
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.
EPSS 1.24% · 66.9th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.24%
66.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | drupal | 8.0.0, 9.1.0, 9.2.0 |
| Bitnami | drupal | 9.1.0, 9.2.0, 8.0.0 |
Timeline
- Sep 15, 2021 CVE Published
- Feb 12, 2022 EPSS Score
- Feb 23, 2022 CVE Updated
- Apr 5, 2022 EPSS Score
- May 28, 2022 EPSS Score
- Jul 20, 2022 EPSS Score
- Sep 11, 2022 EPSS Score
- Nov 2, 2022 EPSS Score
- Dec 25, 2022 EPSS Score
- Feb 15, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 9, 2023 EPSS Score