—
DRUPAL-CONTRIB-2022-044
Details
Entity Browser Block provides a Block Plugin for every Entity Browser on your site.
The module didn't sufficiently check entity view access in the block form.
This vulnerability is mitigated by the fact that an attacker must be able to place a block - either through the core "Block Layout" page or via a module like Layout Builder.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/entity_browser_block
Introduced in:
0Fixed in: 1.2.0Upgrade drupal/entity_browser_block to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).