CVE-2025-14840
Description
A flaw was found in the Drupal Http Client Manager module. This module, which allows administrators to configure HTTP requests, does not adequately separate data from request operations. This oversight could potentially lead to the disclosure of sensitive information under specific, uncommon circumstances.
Statement
This vulnerability doesn't affect any supported Red Hat product.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity; Bypass Protection Mechanism
The exploitation of a weakness in low-privileged areas of the software can be leveraged to reach higher-privileged areas without having to overcome any additional obstacles.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.