{ "canonical_id": "drupal--4a0d8893d5", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004", "summary": "
Drupal's uniqueness checking for certain user fields is inconsistent depending on the database engine and its collation.
\nAs a result, a user may be able to register with the same email address as another user.
\nThis may lead to data integrity issues.
Install the latest version:
\nAll versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
\nUpdating Drupal will not solve potential issues with existing accounts affected by this bug. See Fixing emails that vary only by case for additional guidance.