DRUPAL-CONTRIB-2025-099

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/facets/DRUPAL-CONTRIB-2025-099.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2025-099
Aliases
  • CVE-2025-9549
Published
2025-08-27T17:19:24Z
Modified
2025-12-10T23:41:24.299430Z
Summary
[none]
Details

This module enables you to to easily create and manage faceted search interfaces.

The module doesn't sufficiently check access to entities when they are displayed as facets.

This vulnerability is mitigated by the fact that only sites that show facets with entity labels (like taxonomy terms) are affected, and only if some of those entities are unpublished or have other access restrictions.

CVSS risk score (experimental) 6.9 / Medium

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/facets

Package

Name
drupal/facets
Purl
pkg:composer/drupal/facets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.10
Database specific
{
    "constraint": "<2.0.10"
}
Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.1
Database specific
{
    "constraint": ">=3.0.0 <3.0.1"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/facets/DRUPAL-CONTRIB-2025-099.json"
affected_versions
"<2.0.10 || >=3.0.0 <3.0.1"