VDB

CVE-2020-13675

CVE-2020-13675 PUBLISHED CVSS 9.800000190734863 CRITICAL

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

EPSS 1.24% · 66.9th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.24%
66.9th percentile

Affected Products

VendorProductVersions
Bitnamidrupal8.0.0, 9.1.0, 9.2.0
Bitnamidrupal9.1.0, 9.2.0, 8.0.0

Timeline

  • Sep 15, 2021 CVE Published
  • Feb 12, 2022 EPSS Score
  • Feb 23, 2022 CVE Updated
  • Apr 5, 2022 EPSS Score
  • May 28, 2022 EPSS Score
  • Jul 20, 2022 EPSS Score
  • Sep 11, 2022 EPSS Score
  • Nov 2, 2022 EPSS Score
  • Dec 25, 2022 EPSS Score
  • Feb 15, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 9, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›