—
DRUPAL-CONTRIB-2022-059
Details
This module enables you to build searches using a wide range of features, data sources and backends.
The module doesn't in all cases correctly detect whether a given search is active on the current page, leading to potential information disclosure for some setups.
This vulnerability is mitigated by the fact that only very specific setups will have this problem and there is no way for an attacker to trigger it.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/search_api
Introduced in:
0Fixed in: 1.27.0Upgrade drupal/search_api to 1.27.0 or newer (ecosystem packagist:https://packages.drupal.org/8).