CVE-2025-14840

Description

A flaw was found in the Drupal Http Client Manager module. This module, which allows administrators to configure HTTP requests, does not adequately separate data from request operations. This oversight could potentially lead to the disclosure of sensitive information under specific, uncommon circumstances.

Statement

This vulnerability doesn't affect any supported Red Hat product.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity; Bypass Protection Mechanism

The exploitation of a weakness in low-privileged areas of the software can be leveraged to reach higher-privileged areas without having to overcome any additional obstacles.

Frequently Asked Questions

Want to get errata notifications? Sign up here.