Drupal core access bypass vulnerability
High severity
GitHub Reviewed
Published
Feb 12, 2022
to the GitHub Advisory Database
•
Updated Oct 4, 2023
Package
Affected versions
>= 8.0.0, < 8.9.19
>= 9.1.0, < 9.1.13
>= 9.2.0, < 9.2.6
Patched versions
8.9.19
9.1.13
9.2.6
Description
Published by the National Vulnerability Database
Feb 11, 2022
Published to the GitHub Advisory Database
Feb 12, 2022
Last updated
Oct 4, 2023
Reviewed
Oct 4, 2023
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
References