The Workspaces module didn’t sufficiently check access permissions when switching workspaces, leading to an access bypass vulnerability. An attacker could be able to see content before the site owner intends people to see the content.
This vulnerability affects the following application versions:
- Drupal 8.8.0
- Drupal 8.8.1
- Drupal 8.8.2
- Drupal 8.8.3
- Drupal 8.8.4
- Drupal 8.8.5
- Drupal 8.8.6
- Drupal 8.8.7
- Drupal 8.8.8
- Drupal 8.8.9
- Drupal 8.9.0
- Drupal 8.9.1
- Drupal 8.9.2
- Drupal 8.9.3
- Drupal 8.9.4
- Drupal 8.9.5
- Drupal 9.0.0
- Drupal 9.0.1
- Drupal 9.0.2
- Drupal 9.0.3
- Drupal 9.0.4
- Drupal 9.0.5