VDB
Sign up
—

DRUPAL-CONTRIB-2022-025

Details

This advisory addresses a similar issue to [Drupal core - Moderately critical - Information disclosure - SA-CORE-2022-004](https://www.drupal.org/sa-core-2022-004).

The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/quickedit
Introduced in: 0Fixed in: 1.0.1

Upgrade drupal/quickedit to 1.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

References