Easy Breadcrumb
It shows a trail of links for category hierarchies on a page.
A visitor could see the names of unpublished parent categories in the website trail. They could read these hidden names. They could not open those pages or change anything.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the add parent hierarchy setting is enabled and at least one category has an unpublished parent category.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Easy Breadcrumb to 2.0.11.
For developers: what the fix changed
The fix introduces a view access check, $parent->access('view'), for parent taxonomy terms in the build method of src/EasyBreadcrumbBuilder.php, so users cannot see breadcrumb segments for unpublished or otherwise restricted terms.
Also in this release Other changes include cache context and tag updates, HTML tag stripping for breadcrumb items, fixes for admin route exclusions, and test implementations.
composer.json+2 −0easy_breadcrumb.module+35 −1easy_breadcrumb.services.yml+6 −1src/Cache/EasyBreadcrumbCacheContext.php+74 −0src/EasyBreadcrumbBuilder.php+81 −69 fixsrc/EasyBreadcrumbStructuredDataJsonLd.php+4 −12src/Form/EasyBreadcrumbGeneralSettingsForm.php+1 −3src/TitleResolver.php+7 −14