The Settings Tray module had a vulnerability that allowed users to update certain data that they did not have the permissions for.
If you had implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but did not harden against other such bypasses.
This vulnerability could be mitigated by disabling the Settings Tray module.
Part of security release SA-CORE-2018-001
This vulnerability affects the following application versions:
- Drupal 8.2.0
- Drupal 8.2.1
- Drupal 8.2.2
- Drupal 8.2.3
- Drupal 8.2.4
- Drupal 8.2.5
- Drupal 8.2.6
- Drupal 8.2.7
- Drupal 8.2.8
- Drupal 8.3.0
- Drupal 8.3.1
- Drupal 8.3.2
- Drupal 8.3.3
- Drupal 8.3.4
- Drupal 8.3.5
- Drupal 8.3.6
- Drupal 8.3.7
- Drupal 8.4.0
- Drupal 8.4.1
- Drupal 8.4.2
- Drupal 8.4.3
- Drupal 8.4.4