Incorrect authorization in Drupal core
Moderate severity
GitHub Reviewed
Published
Feb 18, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
>= 9.3.0, < 9.3.6
>= 8.0.0, < 9.2.13
Patched versions
9.3.6
9.2.13
Description
Published by the National Vulnerability Database
Feb 17, 2022
Published to the GitHub Advisory Database
Feb 18, 2022
Reviewed
Mar 1, 2022
Last updated
Feb 3, 2023
The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
References