Entity Reference Manager (Merge entities)
It allows administrators to identify, analyse, and replace references to pieces of content across the system.
A regular visitor who can view pages could use the merging tool to delete content. They could destroy web pages, media files, or categories. They could also read and alter some restricted details.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Entity Reference Manager (Merge entities) to 1.0.3.
For developers: what the fix changed
The fix adds permission checks to the routing configuration in entity_reference_manager.routing.yml and enforces strict access validation in the execute method of src/Service/ContentMergeManager.php. It also marks the administration permission as restricted in entity_reference_manager.permissions.yml.
entity_reference_manager.permissions.yml+1 −0 fixentity_reference_manager.routing.yml+3 −0 fixentity_reference_manager.services.yml+1 −0 fixsrc/Service/ContentMergeManager.php+20 −0 fix