—
DRUPAL-CONTRIB-2019-067
Details
This module allows you to attach tabular data to an entity.
There is insufficient access checking for users with the ability to "Export Tablefield Data as CSV". They can export data from unpublished nodes or otherwise inaccessible entities.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Export Tablefield Data as CSV".
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/tablefield
Introduced in:
0Fixed in: 2.1.0Upgrade drupal/tablefield to 2.1.0 or newer (ecosystem packagist:https://packages.drupal.org/8).