CVE-2015-4344: Services Basic Authentication Project Services Basic Authentication

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.

Affected products

Published 2015-06-15. Last modified 2026-06-17.