<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Drupal (11.x-Dev) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/drupal-11.x-dev/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 16:37:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/drupal-11.x-dev/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Full Path Disclosure Vulnerability in Drupal 11.x-dev</title><link>https://feed.craftedsignal.io/briefs/2026-10-drupal-path-disclosure/</link><pubDate>Fri, 02 Oct 2026 16:37:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-drupal-path-disclosure/</guid><description>CVE-2024-45440 is a full path disclosure vulnerability in Drupal 11.x-dev allowing unauthenticated attackers to leak server-side filesystem paths via the authorize.php endpoint.</description><content:encoded><![CDATA[<p>CVE-2024-45440 is a security vulnerability in Drupal 11.x-dev that enables an unauthenticated attacker to perform full path disclosure. The flaw resides within the <code>core/authorize.php</code> component. When the application attempts to process the <code>hash_salt</code> parameter, an improper execution of <code>file_get_contents</code> on a non-existent or misconfigured file can trigger an error response that reveals the absolute path of the Drupal installation on the underlying server. While the vulnerability is classified as medium severity (CVSS 5.3), the exposure of internal filesystem structures provides attackers with reconnaissance data that facilitates more complex, targeted attacks. Publicly available exploit scripts automate the discovery process, increasing the risk for organizations running development or pre-release versions of the Drupal core.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target server running Drupal 11.x-dev.</li>
<li>Attacker probes the endpoint <code>/core/authorize.php</code> to determine if it is reachable.</li>
<li>Attacker submits a specially crafted HTTP request targeting the <code>hash_salt</code> parameter.</li>
<li>The vulnerable <code>core/authorize.php</code> script triggers a <code>file_get_contents</code> operation on an invalid file path.</li>
<li>The application fails to handle the error properly, generating an error log that includes the full server-side path.</li>
<li>The server returns the path information in the HTTP response body to the attacker.</li>
<li>Attacker uses the disclosed path information to plan further reconnaissance or exploit attempts against the server infrastructure.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the leakage of sensitive internal filesystem paths. While not providing direct remote code execution, this information disclosure is a critical reconnaissance step. It allows adversaries to map server directory structures, facilitating the identification of configuration files, backup files, or other sensitive resources that could be targeted in secondary attacks. The vulnerability affects Drupal 11.x-dev versions.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Identify and upgrade all instances of Drupal 11.x-dev to a patched, stable release that remediates this disclosure flaw.</li>
<li>Restrict public access to administrative and installation-related scripts, specifically <code>core/authorize.php</code>, if they are not required for normal site operation.</li>
<li>Deploy the webserver-level detection rule below to monitor for exploitation attempts against the <code>authorize.php</code> endpoint.</li>
<li>Review web access logs for 200/500 status codes originating from suspicious query strings containing <code>hash_salt</code>.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>drupal</category><category>reconnaissance</category></item></channel></rss>