Content Entity Clone - Moderately critical - Information Disclosure - SA-CONTRIB-2024-035

Джерело:
Security advisories for contributed projects

Дата публікації:
04/09/2024 18:40

Постійна адреса новини:
http://www.vsinovyny.com/11264076

Content Entity Clone - Moderately critical - Information Disclosure - SA-CONTRIB-2024-035

 

04/09/2024 18:40 // Security advisories for contributed projects

Project: 
Date: 
2024-September-04
Security risk: 
Vulnerability: 
Information Disclosure
Affected versions: 
<1.0.4
Description: 

This module enables you to "clone" a content entity, i.e. to create a new content pre-filled with data from another entity of the same type and bundle.

The module doesn't properly check the user access to the original entity, allowing users to create a new entity (they have permission to create) pre-filled with content from another entity of the same type and bundle that they would normally not have access to.

This vulnerability is mitigated by the fact that an attacker must have the permission to create content of the type of the entity to clone.

Solution: 

Install the latest version:

Reported By: 
Fixed By: 
Coordinated By: 

 

» Читати повністю

 

« Наступна новина з архіву
Paragraphs table - Critical - Access bypass, Information Disclosure - SA-CONTRIB-2024-036
  Попередня новина з архіву
Freelinking - Moderately critical - Information Disclosure - SA-CONTRIB-2024-034
»

 

 
© 2026 www.vsinovyny.com