CVE-2024-13291: Basic HTTP Authentication Project Basic HTTP Authentication
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.
Affected products
- Basic HTTP Authentication Project Basic HTTP Authentication: before 7.x-1.4 (fixed in 7.x-1.4)
Published 2025-01-09. Last modified 2026-06-17.