{"id":"DRUPAL-CONTRIB-2024-070","details":"The Minify JS module allows a site administrator to minify all javascript files that exist in the site's code base and use those minified files on the front end of the website.\n\nSeveral administrator routes are unprotected against Cross-Site Request Forgery (CRSF) attacks.","aliases":["CVE-2024-13304"],"modified":"2026-09-10T03:46:09.753517148Z","published":"2024-12-04T15:51:12Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-070"}],"affected":[{"package":{"name":"drupal/minifyjs","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/minifyjs?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.3"}],"database_specific":{"constraint":"\u003c3.0.3"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/minifyjs/DRUPAL-CONTRIB-2024-070.json","affected_versions":"\u003c3.0.3"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff","contact":["https://www.drupal.org/user/3611858"]}]}