Diff
A visitor could see the history of changes for certain pieces of data if they already had the access right to view the current version. They could read past versions of this data that should have been kept private. They could not make any changes to the content or its history.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Diff to 2.0.1 or 2.1.1, whichever branch you are on.
For developers: what the fix changed
The fix updates the entity access requirement in src/Routing/DiffRouteProvider.php to check for the 'view all revisions' permission instead of just the 'view' permission.
src/Routing/DiffRouteProvider.php+1 −1 fix