Miggo Logo

CVE-2025-48448:
Drupal Admin Audit Trail Allocation of Resources Without Limits or Throttling vulnerability

7.5

CVSS Score

Basic Information

EPSS Score
-
Published
6/11/2025
Updated
6/11/2025
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
drupal/admin_audit_trailcomposer< 1.0.51.0.5

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability (CVE-2025-48448) in the Drupal Admin Audit Trail module (versions prior to 1.0.5) is an 'Allocation of Resources Without Limits or Throttling' issue. According to the Drupal security advisory (SA-CONTRIB-2025-068), this occurs when the 'Admin Audit Trail: User Authentication' submodule is enabled. The module fails to sufficiently limit large values before logging user authentication events (login, logout, password reset requests), leading to excessive resource allocation and a potential denial of service. Without access to the specific patch or source code changes, it's impossible to pinpoint the exact vulnerable functions. However, the vulnerability lies within the logging mechanism of the user authentication submodule. Functions responsible for handling and logging these authentication events would be the ones to examine. The fix in version 1.0.5 likely introduced input validation or truncation for the data being logged.

Confidence is low because I could not retrieve the commit information or source code to verify the exact functions involved. The analysis is based on the description of the vulnerability in the advisories.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*llo**tion o* R*sour**s Wit*out Limits or T*rottlin* vuln*r**ility in *rup*l **min *u*it Tr*il *llows *x**ssiv* *llo**tion. T*is issu* *****ts **min *u*it Tr*il: *rom *.*.* ***or* *.*.*.

Reasoning

T** vuln*r**ility (*V*-****-*****) in t** *rup*l **min *u*it Tr*il mo*ul* (v*rsions prior to *.*.*) is *n '*llo**tion o* R*sour**s Wit*out Limits or T*rottlin*' issu*. ***or*in* to t** *rup*l s**urity **visory (S*-*ONTRI*-****-***), t*is o**urs w**n