Published:2024/01/16  Last Updated:2024/01/16

JVN#63383723
Drupal vulnerable to improper handling of structural elements

Overview

Drupal contains an improper handling of structural elements vulnerability.

Products Affected

  • Drupal
The reporter states that Drupal version 9.3.6 was found to be vulnerable to this issue.
The developer states that this vulnerability was not reproduced in the version 10 series and the latest version 9.5.x of the version 9 series.

Description

Drupal provided by Drupal.org contains an improper handling of structural elements vulnerability (CWE-237).

Impact

An attacker may be able to cause a denial-of-service (DoS) condition.

Solution

Update the Software
Update the software to the latest version (10 series) according to the information provided by the developer.

The support for Drupal version 9 series came to an end (EOL) in November 2023.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score: 5.3
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)
CVSS v2 AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score: 5.0
Access Vector(AV) Local (L) Adjacent Network (A) Network (N)
Access Complexity(AC) High (H) Medium (M) Low (L)
Authentication(Au) Multiple (M) Single (S) None (N)
Confidentiality Impact(C) None (N) Partial (P) Complete (C)
Integrity Impact(I) None (N) Partial (P) Complete (C)
Availability Impact(A) None (N) Partial (P) Complete (C)

Credit

Shiga Takuma of BroadBand Security Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2024-22362
JVN iPedia JVNDB-2024-000004