—
DRUPAL-CORE-2020-006
Quick fix
DRUPAL-CORE-2020-006 — drupal/core: upgrade to the fixed version with the command below.
composer require drupal/core:^8.8.8Details
JSON:API PATCH requests may bypass validation for certain fields.
By default, JSON:API works in a read-only mode which makes it impossible to exploit the vulnerability. Only sites that have the `read_only` set to `FALSE` under `jsonapi.settings` config are vulnerable.
Are you affected?
Enter the version of the package you're using.