Vulnerability Bulletins

Drupal core - Moderately critical - Access bypass - SA-CORE-2020-008


System information

   
Affected software Drupal

Description

Project: Drupal coreDate: 2020-September-16Security risk: Moderately critical 12∕25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Access bypassCVE IDs: CVE-2020-13667Description: The experimental Workspaces module allows you to create multiple workspaces on your site in which draft content can be edited before being published to the live workspace.The Workspaces module doesnt sufficiently check access permissions when switching workspaces, leading to an access

More info:

https://www.drupal.org/sa-core-2020-008

Standar resources

Property Value
CVE CVE-2020-13667.

Version history

Version Comments Date
1.0 Advisory issued 2020-09-17
Ministerio de Defensa
CNI
CCN
CCN-CERT