{"id":"GHSA-mh4h-27gq-cxwj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mh4h-27gq-cxwj","summary":"Drupal core Access bypass","details":"The Media Library module has a security vulnerability whereby it doesn't sufficiently restrict access to media items in certain configurations.\n\nSolution:\nIf you are using Drupal 8.7.x, you should upgrade to Drupal 8.7.11.\nIf you are using Drupal 8.8.x, you should upgrade to Drupal 8.8.1.\nVersions of Drupal 8 prior to 8.7.x are end-of-life and do not receive security coverage.\n\nAlternatively, you may mitigate this vulnerability by unchecking the \"Enable advanced UI\" checkbox on `/admin/config/media/media-library`. (This mitigation is not available in 8.7.x.)","published":"2024-05-15T20:44:16Z","modified":"2024-11-29T05:44:49.819622Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.7.11"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.8.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/2019-12-18-3.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/core"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2019-011"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:44:49.819622Z"}}