---
cve: "CVE-2020-13665"
severity: "LOW"
cvss: 3.1
epss: "1.3%"
vendor: "Drupal"
kev: false
exploited: false
published: "2021-05-05 15:15:08"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T16:38:34+02:00"
---

# CVE-2020-13665

> 3.1 LOW

## Beschreibung

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API is in read/write mode. Only sites that have the read_only set to FALSE under jsonapi.settings config are vulnerable. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.x versions prior to 9.0.1.

## Patch verfügbar (OSV)

- d6ae9678b5c51ab3d7cb63746abacba61bb6cdb8 (Commit)
- 4aff4012073fb3bf45218b8af9f2eadc4ea69470 (Commit)

## Referenzen

- <https://www.drupal.org/sa-core-2020-006>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-13665) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
