Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069


Chronologisch Thread 
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069
  • Date: Wed, 25 Sep 2019 16:48:20 +0000 (UTC)
  • List-archive: <http://lists.drupal.org/pipermail/security-news/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2019-069

Project: Gutenberg [1]
Date: 2019-September-25
Security risk: *Critical* 16∕25
AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Description: 
This module provides a new UI experience for node editing - Gutenberg editor.

The routes used by the Gutenberg editor lack proper permissions allowing
untrusted users to view and modify some content they should not be able to
view or modify.

Solution: 
Install the latest version:

* If you use the Gutenberg module 8.x-1.x, upgrade to 8.x-1.8 [3]
* For roles other than administrator, the Administer Gutenberg permission
must be given to handle media files on the Gutenberg editor.

Also see the Gutenberg [4] project page.

Reported By: 
* Marco Fernandes [5]
* Greg Knaddison [6] of the Drupal Security Team

Fixed By: 
* Marco Fernandes [7]
* Thor Andre Gretland [8]
* Mariusz Andrzejewski [9]

Coordinated By: 
* Greg Knaddison [10] of the Drupal Security Team


[1] https://www.drupal.org/project/gutenberg
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/gutenberg/releases/8.x-1.8
[4] https://www.drupal.org/project/gutenberg
[5] https://www.drupal.org/user/2127558
[6] https://www.drupal.org/user/36762
[7] https://www.drupal.org/user/2127558
[8] https://www.drupal.org/user/223878
[9] https://www.drupal.org/user/3517832
[10] https://www.drupal.org/user/36762

_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news


  • [IT-SecNots] [Security-news] Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069, security-news, 25.09.2019

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang