CVE-2024-11941

A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.
References
Link Resource
https://www.drupal.org/sa-core-2024-001 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

History

02 Jun 2025, 16:18

Type Values Removed Values Added
First Time Drupal
Drupal drupal
References () https://www.drupal.org/sa-core-2024-001 - () https://www.drupal.org/sa-core-2024-001 - Vendor Advisory
Summary
  • (es) Una vulnerabilidad en Drupal Core permite una asignación excesiva. Este problema afecta a Drupal Core: desde 10.2.0 hasta 10.2.2, desde 10.1.0 hasta 10.1.8.
CPE cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

05 Dec 2024, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

05 Dec 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-05 15:15

Updated : 2025-06-02 16:18


NVD link : CVE-2024-11941

Mitre link : CVE-2024-11941

CVE.ORG link : CVE-2024-11941


JSON object : View

Products Affected

drupal

  • drupal
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')