-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from inconsistent access query tag naming in taxonomy module access control. The taxonomy_term_query_access_alter function in Drupal's taxonomy module is responsible for adding access restrictions to taxonomy term queries. Before the patch, it used different query tags ('term_access') than other core entity types, failing to trigger proper access checks. This allowed authenticated users to see taxonomy terms without proper authorization by exploiting the tag naming inconsistency in query alterations.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/core | composer | >= 7.0, < 7.52 | 7.52 |
| drupal/core | composer | >= 8.0, < 8.2.3 | 8.2.3 |
| drupal/drupal | composer |
| >= 8.0, < 8.2.3 |
| 8.2.3 |
| drupal/drupal | composer | >= 7.0, < 7.52 | 7.52 |
Ongoing coverage of React2Shell