Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9026 | Drupal OAuth2 Server Missing Authorization vulnerability |
Github GHSA |
GHSA-4f8q-mwgc-3mwc | Drupal OAuth2 Server Missing Authorization vulnerability |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-020 |
|
Tue, 02 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oauth2 Server Project
Oauth2 Server Project oauth2 Server |
|
| CPEs | cpe:2.3:a:oauth2_server_project:oauth2_server:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Oauth2 Server Project
Oauth2 Server Project oauth2 Server |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0. | |
| Title | OAuth2 Server - Moderately critical - Access bypass - SA-CONTRIB-2025-020 | |
| Weaknesses | CWE-862 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:20:48.207Z
Reserved: 2025-03-31T21:30:15.360Z
Link: CVE-2025-31691
Updated: 2025-04-29T15:20:43.078Z
Status : Analyzed
Published: 2025-03-31T22:15:21.737
Modified: 2025-09-02T18:35:15.883
Link: CVE-2025-31691
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA