CVE-2013-1946
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
06/04/2014
Last modified:
12/04/2025
Description
The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:restful_web_services_project:restful_web_services:7.x-1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:restful_web_services_project:restful_web_services:7.x-1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:restful_web_services_project:restful_web_services:7.x-2.0:alpha3:*:*:*:*:*:* | ||
| cpe:2.3:a:restful_web_services_project:restful_web_services:7.x-2.0:alpha4:*:*:*:*:*:* | ||
| cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2013/04/12/1
- http://www.osvdb.org/92259
- https://drupal.org/node/1966752
- https://drupal.org/node/1966758
- https://drupal.org/node/1966780
- http://www.openwall.com/lists/oss-security/2013/04/12/1
- http://www.osvdb.org/92259
- https://drupal.org/node/1966752
- https://drupal.org/node/1966758
- https://drupal.org/node/1966780



