Entity API
Anyone without logging in could use a data feed to view lists of content. This would allow them to read private information that should be hidden. They could not change any of this information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the data feed module is also turned on.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Entity API to 8.x-1.8.
For developers: what the fix changed
Removes the default allowed access result when there are no conditions in entity_jsonapi_entity_filter_access within entity.module.
Also in this release Adds a functional test for JSON:API terms.
entity.module+1 −4 fix