CVE-2024-45440: Drupal Full Path Disclosure
(updated )
core/authorize.php
in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt
is file_get_contents
of a file that does not exist.
References
- github.com/advisories/GHSA-mg8j-w93w-xjgc
- github.com/drupal/drupal
- github.com/github/advisory-database/pull/4827
- nvd.nist.gov/vuln/detail/CVE-2024-45440
- senscybersecurity.nl/CVE-2024-45440-Explained
- www.drupal.org/project/drupal/issues/3457781
- www.drupal.org/project/drupal/releases/10.2.9
- www.drupal.org/project/drupal/releases/10.3.6
- www.drupal.org/project/drupal/releases/11.0.5
Detect and mitigate CVE-2024-45440 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →