Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069

Gutenberg - Critical - Access bypass - SA-CONTRIB-2019-069

Project: Gutenberg
Date: 2019-September-25
Security risk: Critical 16∕25 
Vulnerability: Access bypass

Description

This module provides a new UI experience for node editing - Gutenberg editor.

The routes used by the Gutenberg editor lack proper permissions allowing untrusted users to view and modify some content they should not be able to view or modify.

Solution

Install the latest version:

If you use the Gutenberg module 8.x-1.x, upgrade to 8.x-1.8
For roles other than administrator, the Administer Gutenberg permission must be given to handle media files on the Gutenberg editor.
Also see the Gutenberg project page.

https://www.drupal.org/sa-contrib-2019-069

Nick Onom's picture
Nick Onom
Marketing Project Manager
Enthusiastic about all kind of Open Source applications, AI, bitcoins, but mostly about Drupal. For last years has been actively developing AltaGrade's new back-end system.

We value your opinion. Please add your feedback.