Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9033 | Drupal Configuration Split Cross-Site Request Forgery (CSRF) vulnerability |
Github GHSA |
GHSA-qq45-cqhg-jwx5 | Drupal Configuration Split Cross-Site Request Forgery (CSRF) vulnerability |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-017 |
|
Thu, 28 Aug 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuvole
Nuvole configuration Split |
|
| CPEs | cpe:2.3:a:nuvole:configuration_split:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Nuvole
Nuvole configuration Split |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This issue affects Configuration Split: from 0.0.0 before 1.10.0, from 2.0.0 before 2.0.2. | |
| Title | Configuration Split - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-017 | |
| Weaknesses | CWE-352 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:28:10.316Z
Reserved: 2025-03-31T21:30:15.360Z
Link: CVE-2025-31688
Updated: 2025-04-29T15:26:18.299Z
Status : Analyzed
Published: 2025-03-31T22:15:21.413
Modified: 2025-08-28T14:54:03.030
Link: CVE-2025-31688
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA