—
DRUPAL-CONTRIB-2024-048
Details
This module provides a new UI experience for node editing using the Gutenberg Editor library.
The module did not sufficiently protect some routes against a Cross Site Request Forgery attack.
This vulnerability is mitigated by the fact that the tricked user needs to have an active session with the "use gutenberg" permission.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/gutenberg
Introduced in:
0Fixed in: 2.13.0Upgrade drupal/gutenberg to 2.13.0 or newer (ecosystem packagist:https://packages.drupal.org/8).