The Settings Tray module had a vulnerability that allowed users to update certain data that they did not have the permissions for.

If you had implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but did not harden against other such bypasses.

This vulnerability could be mitigated by disabling the Settings Tray module.

Part of security release SA-CORE-2018-001

This vulnerability affects the following application versions:

  • Drupal 8.2.0
  • Drupal 8.2.1
  • Drupal 8.2.2
  • Drupal 8.2.3
  • Drupal 8.2.4
  • Drupal 8.2.5
  • Drupal 8.2.6
  • Drupal 8.2.7
  • Drupal 8.2.8
  • Drupal 8.3.0
  • Drupal 8.3.1
  • Drupal 8.3.2
  • Drupal 8.3.3
  • Drupal 8.3.4
  • Drupal 8.3.5
  • Drupal 8.3.6
  • Drupal 8.3.7
  • Drupal 8.4.0
  • Drupal 8.4.1
  • Drupal 8.4.2
  • Drupal 8.4.3
  • Drupal 8.4.4

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *