CVE-2022-25274
- EPSS 0.17%
- Published 26.04.2023 14:15:09
- Last modified 03.02.2025 19:15:08
Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content general...
CVE-2022-25275
- EPSS 0.31%
- Published 26.04.2023 14:15:09
- Last modified 03.02.2025 19:15:09
In some situations, the Image module does not correctly check access to image files not stored in the standard public files directory when generating derivative images using the image styles system. Access to a non-public file is checked only if it i...
CVE-2022-39261
- EPSS 1.57%
- Published 28.09.2022 14:15:10
- Last modified 21.11.2024 07:17:54
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `in...
CVE-2022-31042
- EPSS 0.74%
- Published 10.06.2022 00:15:07
- Last modified 21.11.2024 07:03:46
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on ...
CVE-2022-31043
- EPSS 0.95%
- Published 10.06.2022 00:15:07
- Last modified 21.11.2024 07:03:46
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we ...
CVE-2022-29248
- EPSS 0.45%
- Published 25.05.2022 18:15:08
- Last modified 21.11.2024 06:58:48
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the ...
CVE-2022-24775
- EPSS 0.67%
- Published 21.03.2022 19:15:11
- Last modified 21.11.2024 06:51:04
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There ar...
CVE-2022-24729
- EPSS 0.51%
- Published 16.03.2022 17:15:07
- Last modified 21.11.2024 06:50:57
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a ...
CVE-2022-24728
- EPSS 0.72%
- Published 16.03.2022 16:15:10
- Last modified 21.11.2024 06:50:57
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to in...
CVE-2022-25270
- EPSS 0.25%
- Published 17.02.2022 00:15:07
- Last modified 21.11.2024 06:51:55
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the Qui...