Impact
An incorrect authorization rule in the Drupal Diff module permits forceful browsing, allowing attackers to bypass permissions and access content that should be restricted. This weakness, identified as CWE-863, means that anyone can read protected Diff entries without authenticating or possessing elevated rights.
Affected Systems
Drupal sites employing the Diff module versions 0.0.0 through 2.0.1 or 2.1.0 through 2.1.1 are impacted. The issue applies to any deployment of these releases, regardless of other site configuration.
Risk and Exploitability
The vulnerability can be exploited remotely via an HTTP request to the Diff module endpoints. Based on the description, it is inferred that the likely attack vector is a standard web request and that no special privileges are required for exploitation. The CVSS score of 5.3 indicates a moderate severity level. EPSS data is unavailable, and the flaw is not listed in CISA KEV. Given its access‑bypass nature, the flaw could allow unprivileged users to retrieve confidential content.
OpenCVE Enrichment