← Back

CVE-2020-13665

nvd nist
Published: May 5, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.

Affected (3)

Products: Drupal: Drupal
1 product
Drupal
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
From 8.8.0 to 8.8.8
From 8.9.0 to 8.9.1
From 9.0.0 to 9.0.1

References (2)

Source: mlhess@drupal.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.