CVE Database
/

CVE-2024-45440

Back to search

CVE-2024-45440

Published: Aug 29, 2024

Modified: Apr 21, 2025

PUBLISHED

Description

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.

VendorProductVersions

Drupal

Drupal core

affected
v11.x-dev

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now