Drupal editor module incorrectly checks access to inline private files
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 3, 2024
Description
Published by the National Vulnerability Database
Mar 16, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 23, 2024
Last updated
May 3, 2024
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
References