Blazy
An ordinary account on the site could use a special text code to display a specific part of a piece of content they are not allowed to view. This would let them read private information from that specific part. They could not change any information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if a user has access to a text format that uses this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate Blazy to 3.0.18.
For developers: what the fix changed
The provided diff does not appear to contain the fix for the access bypass vulnerability, as there are no changes related to entity view access checks or filter plugin shortcode rendering logic.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release refactored hooks for Drupal 12 compatibility, updated documentation, modified JavaScript for media handling, and adjusted service definitions.
.eslintignore+11 −0.eslintrc.json+2 −1.gitattributes+6 −0.gitignore+4 −0.gitlab-ci.yml+5 −0CHANGELOG.txt+51 −0blazy.api.php+38 −4blazy.install+1 −1blazy.libraries.yml+7 −4blazy.module+20 −109blazy.services.yml+74 −35config/install/blazy.settings.yml+2 −0