drupal/tca is vulnerable to Access Bypass
50
Medium Risk
The Token Content Access module is vulnerable to an authentication bypass due to a timing side-channel in access token comparison. In certain cases, access tokens are not compared using a constant-time operation, allowing an attacker to infer valid token values by measuring response time differences. A successful attack could enable unauthorized access to content protected by the module. Exploitation requires the attacker to know or discover the URL of protected content and perform a sufficient number of timing measurements to recover a valid access token.
You are affected if you are using a version that falls within the vulnerable range.
drupal/tca is vulnerable to Access Bypass in versions 0.0.1 - 3.1.1.
Upgrade the drupal/tca library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant