GHSA-x2q9-r8gm-f657

Suggest an improvement
Source
https://github.com/advisories/GHSA-x2q9-r8gm-f657
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x2q9-r8gm-f657/GHSA-x2q9-r8gm-f657.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x2q9-r8gm-f657
Aliases
Published
2022-05-24T19:02:37Z
Modified
2024-04-23T22:58:53.537679Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Drupal Core Access bypass vulnerability
Details

Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker might be able to see content before the site owner intends people to see the content. This vulnerability is mitigated by the fact that sites are only vulnerable if they have installed the experimental Workspaces module. This issue affects Drupal Core8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

Database specific
{
    "nvd_published_at": "2021-05-17T17:15:00Z",
    "cwe_ids": [
        "CWE-276"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-23T22:30:49Z"
}
References

Affected packages

Packagist / drupal/core

Package

Name
drupal/core
Purl
pkg:composer/drupal/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.8.0
Fixed
8.8.10

Affected versions

8.*

8.8.0
8.8.1
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.8.7
8.8.8
8.8.9

Packagist / drupal/core

Package

Name
drupal/core
Purl
pkg:composer/drupal/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.9.0
Fixed
8.9.6

Affected versions

8.*

8.9.0
8.9.1
8.9.2
8.9.3
8.9.4
8.9.5

Packagist / drupal/core

Package

Name
drupal/core
Purl
pkg:composer/drupal/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
9.0.6

Affected versions

9.*

9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5

Packagist / drupal/drupal

Package

Name
drupal/drupal
Purl
pkg:composer/drupal/drupal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.8.0
Fixed
8.8.10

Affected versions

8.*

8.8.0
8.8.1
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.8.7
8.8.8
8.8.9

Packagist / drupal/drupal

Package

Name
drupal/drupal
Purl
pkg:composer/drupal/drupal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.9.0
Fixed
8.9.6

Affected versions

8.*

8.9.0
8.9.1
8.9.2
8.9.3
8.9.4
8.9.5

Packagist / drupal/drupal

Package

Name
drupal/drupal
Purl
pkg:composer/drupal/drupal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
9.0.6

Affected versions

9.*

9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5