DKAN
It enables organisations to build open data portals to import and share tabular data.
A visitor could read imported data tables through data feeds. They could see this hidden information even if the website restricts general access. They could not change or delete any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it does not give the access content access right to visitors without an account.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate DKAN to 4.1.5 or 4.0.4, whichever branch you are on.
For developers: what the fix changed
The fix updates dkan_datastore.routing.yml to replace the generic access requirement with the access content permission requirement for the dkan_datastore.sql_endpoint.post.api route.
modules/dkan_datastore/dkan_datastore.routing.yml+1 −1 fix