Entity PDF
An ordinary account on the site could ask the website to generate a PDF of a piece of content they are not normally allowed to view. This would let them read private information contained in that document. They could not change or add any information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Entity PDF to 2.1.5.
For developers: what the fix changed
The fix adds entity view access checks to the routing requirements in entity_pdf.routing.yml and to the access methods in PdfEntityController and EntityPdfDownload.
entity_pdf.routing.yml+1 −0 fixsrc/Controller/PdfEntityController.php+2 −1 fixsrc/Plugin/Action/EntityPdfDownload.php+6 −3 fix