Drupal Acquia Content Hub Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in Drupal Acquia Content Hub versions prior to 3.6.4 and from 3.7.0 prior to 3.7.3. The vulnerability allows an attacker to trick an admin into exporting an unwanted entity by exploiting insufficient protection on export routes.
Impact
Exploitation of this vulnerability could lead to unauthorized content exports, potentially allowing attackers to manipulate or disrupt content distribution processes.
Remediation
Users of Acquia Content Hub 3.6.x should upgrade to version 3.6.4. Users of Acquia Content Hub 3.7.x should upgrade to version 3.7.3. The latest version, 3.8.0, is also available and includes this security fix along with other improvements.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
