Critical severity9.1NVD Advisory· Published Jan 9, 2025· Updated Jun 17, 2026
CVE-2024-13278
CVE-2024-13278
Description
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*+ 3 more
- cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*range: <1.8.0
- cpe:2.3:a:diff_project:diff:2.0.0:-:*:*:*:drupal:*:*
- cpe:2.3:a:diff_project:diff:2.0.0:beta1:*:*:*:drupal:*:*
- cpe:2.3:a:diff_project:diff:2.0.0:beta2:*:*:*:drupal:*:*
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2024-042nvdThird Party Advisory
News mentions
0No linked articles in our index yet.