VDB
Sign up
—

DRUPAL-CONTRIB-2024-048

Details

This module provides a new UI experience for node editing using the Gutenberg Editor library.

The module did not sufficiently protect some routes against a Cross Site Request Forgery attack.

This vulnerability is mitigated by the fact that the tricked user needs to have an active session with the "use gutenberg" permission.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/gutenberg
Introduced in: 0Fixed in: 2.13.0

Upgrade drupal/gutenberg to 2.13.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References