drupal/key_auth is vulnerable to Access bypass
50
Medium Risk
A security vulnerability in the module may allow users to access another user's authentication keys. The module does not properly isolate or cache per-user data, allowing an attacker with the same permissions to potentially view keys belonging to other users.
You are affected if you are using a version that falls within the vulnerable range and you have the dynamic_page_cache module enabled.
drupal/key_auth is vulnerable to Access bypass in versions 0.0.1 - 2.2.3.
Upgrade the drupal/key_auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.