Vulnerability Bulletins

Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001


System information

   
Affected software Drupal

Description

Project: Drupal coreDate: 2023-January-18Security risk: Moderately critical 12∕25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Information DisclosureAffected versions: >=8.0.0 =9.5.0 =10.0.0 Description: The Media Library module does not properly check entity access in some circumstances. This may result in users with access to edit content seeing metadata about media items they are not authorized to access.The vulnerability is mitigated by the fact that the

More info:

https://www.drupal.org/sa-core-2023-001

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2023-01-19
Ministerio de Defensa
CNI
CCN
CCN-CERT