Impact
The Token Content Access module contains an observable timing discrepancy that an attacker can exploit to brute‑force access tokens. By measuring response times the attacker can discover valid tokens and gain unauthorized access to protected content. The vulnerability is a form of timing‑based side‑channel attack identified as CWE‑208.
Affected Systems
Drupal implementations using the Token Content Access module are affected. All versions from 0.0.0 through 3.1.2 are vulnerable; no information is provided about later releases.
Risk and Exploitability
The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, so formal risk metrics remain limited. The CVSS score of 7.5 denotes a moderately severe threat. With the timing side‑channel the attack can be performed remotely over the web interface, and no privilege or local access is required. The lack of a published fix means the risk remains persistent until an update is applied. Because brute‑forcing tokens can succeed given enough attempts, the overall threat level can be considered moderate to high.
OpenCVE Enrichment