Junglewise Threat Intelligence

CVE-2024-13258: DRUPAL-CONTRIB-2024-022 - Drupal REST & JSON API Authentication module restricts and secures unauthorized access to your Drupal site APIs using different authenticati

CVE-2024-13258 · Severity: info · Published 2024-05-29

Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal REST & JSON API Authentication module restricts and secures unauthorized access to your Drupal site APIs using different authentication methods including Basic Authentication , API Key Authentication , JWT Authentication , OAuth Authentication , External / Third-Party Provider Authentication, etc.

The module doesn't sufficiently control user access when using Basic Authentication.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/rest_api_authentication

Related threats