The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25270.json",
"cna_assigner": "drupal",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "9.3.x"
},
{
"fixed": "9.3.6"
},
{
"introduced": "9.2.x"
},
{
"fixed": "9.2.13"
}
]
}
]
}