—
DRUPAL-CONTRIB-2021-021
Details
This module provides a revision UI for Linky entities.
The module doesn't sufficiently respect access restrictions to certain entities when used in conjunction with specific modules.
This vulnerability is mitigated by the fact that an attacker must have a role with any of the permissions provided by Linky Revision UI, and another affected module must be enabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/linky_revision_ui
Introduced in:
0Fixed in: 2.127.2Upgrade drupal/linky_revision_ui to 2.127.2 or newer (ecosystem packagist:https://packages.drupal.org/8).