Full Path Disclosure Vulnerability in Drupal 11.x-dev
CVE-2024-45440 is a full path disclosure vulnerability in Drupal 11.x-dev allowing unauthenticated attackers to leak server-side filesystem paths via the authorize.php endpoint.
CVE search metadata
CVE search record: CVE-2024-45440. Severity: medium. CVSS: 5.3. EPSS: 9.27%. KEV: no. Product: Drupal (11.x-dev). Brief: Full Path Disclosure Vulnerability in Drupal 11.x-dev. Brief link: https://feed.craftedsignal.io/briefs/2026-10-drupal-path-disclosure/
CVE-2024-45440 is a security vulnerability in Drupal 11.x-dev that enables an unauthenticated attacker to perform full path disclosure. The flaw resides within the core/authorize.php component. When the application attempts to process the hash_salt parameter, an improper execution of file_get_contents on a non-existent or misconfigured file can trigger an error response that reveals the absolute path of the Drupal installation on the underlying server. While the vulnerability is classified as medium severity (CVSS 5.3), the exposure of internal filesystem structures provides attackers with reconnaissance data that facilitates more complex, targeted attacks. Publicly available exploit scripts automate the discovery process, increasing the risk for organizations running development or pre-release versions of the Drupal core.
Attack Chain
- Attacker identifies a target server running Drupal 11.x-dev.
- Attacker probes the endpoint
/core/authorize.phpto determine if it is reachable. - Attacker submits a specially crafted HTTP request targeting the
hash_saltparameter. - The vulnerable
core/authorize.phpscript triggers afile_get_contentsoperation on an invalid file path. - The application fails to handle the error properly, generating an error log that includes the full server-side path.
- The server returns the path information in the HTTP response body to the attacker.
- Attacker uses the disclosed path information to plan further reconnaissance or exploit attempts against the server infrastructure.
Impact
Successful exploitation results in the leakage of sensitive internal filesystem paths. While not providing direct remote code execution, this information disclosure is a critical reconnaissance step. It allows adversaries to map server directory structures, facilitating the identification of configuration files, backup files, or other sensitive resources that could be targeted in secondary attacks. The vulnerability affects Drupal 11.x-dev versions.
Recommendation
- Identify and upgrade all instances of Drupal 11.x-dev to a patched, stable release that remediates this disclosure flaw.
- Restrict public access to administrative and installation-related scripts, specifically
core/authorize.php, if they are not required for normal site operation. - Deploy the webserver-level detection rule below to monitor for exploitation attempts against the
authorize.phpendpoint. - Review web access logs for 200/500 status codes originating from suspicious query strings containing
hash_salt.
Immediate actions
Patch or remove vulnerable Drupal 11.x-dev installations
Threat Hunt
Search logs for unusual access to /core/authorize.php
Data: webserver access logs
Enrichment needed
- Confirmation of patches released by the Drupal community (CTI) To ensure permanent remediation
Mitigations
Restrict access to authorize.php at the web server level
CVE-2024-45440
Detection coverage 1
Detects CVE-2024-45440 Exploitation - Path Disclosure via authorize.php
mediumDetects exploitation attempts targeting the authorize.php endpoint in Drupal 11.x-dev by monitoring for the hash_salt parameter.
Detection queries are available on the platform. Get full rules →