Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal's revision system.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.drupal.org/sa-core-2022-009 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: drupal
Published: 2023-04-26T00:00:00
Updated: 2024-08-03T04:36:06.578Z
Reserved: 2022-02-16T00:00:00
Link: CVE-2022-25274
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-26T14:15:09.300
Modified: 2024-11-21T06:51:55.600
Link: CVE-2022-25274
Redhat
No data.