๐ Drupal core - Moderately critical - Access bypass - SA-CORE-2019-011
๐ก Newskategorie: IT Security Nachrichten
๐ Quelle: drupal.org
The Media Library module has a security vulnerability whereby it doesn't sufficiently restrict access to media items in certain configurations.
- If you are using Drupal 8.7.x, you should upgrade to Drupal 8.7.11.
- If you are using Drupal 8.8.x, you should upgrade to Drupal 8.8.1.
Versions of Drupal 8 prior to 8.7.x are end-of-life and do not receive security coverage.
Alternatively, you may mitigate this vulnerability by unchecking the "Enable advanced UI" checkbox on /admin/config/media/media-library
. (This mitigation is not available in 8.7.x.)
- Adam G-H
- Jess of the Drupal Security Team
- Andrei Mateescu
- Greg Knaddison of the Drupal Security Team
- Alex Bronstein of the Drupal Security Team
- Sean Blommaert
- Lee Rowlands of the Drupal Security Team