{"id":"GHSA-6ccv-8fgf-cjpw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-6ccv-8fgf-cjpw","summary":"Drupal core Denial of Service vulnerability","details":"The Comment module allows users to reply to comments. In certain cases, an attacker could make comment reply requests that would trigger a denial of service (DOS).\n\nSites that do not use the Comment module are not affected.","published":"2024-02-12T22:31:34Z","modified":"2024-11-29T05:26:49.838861Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"10.1.8"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"10.2.2"}],"fix":{"url":"https://github.com/drupal/core/commit/2f76ac716ca8019bc60579fdfc8aa6cd65d57dff","label":"drupal/core@2f76ac7"},"references":[{"type":"WEB","url":"https://github.com/drupal/core/commit/2f76ac716ca8019bc60579fdfc8aa6cd65d57dff"},{"type":"WEB","url":"https://github.com/drupal/core/commit/5e606b560ac4ecb08135f12b6165bbe0348346a0"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/2024-01-17.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/core"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2024-001"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:26:49.838861Z"}}