Gutenberg
It provides a new interface for editing pieces of content using a block editor.
A writer using the visual editor could access restricted parts of the system. They could read hidden information through the editor tools. They could also alter some restricted content.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has a role with the use gutenberg access right.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Gutenberg to 8.x-2.15 or 3.0.7, whichever branch you are on.
For developers: what the fix changed
Adds missing entity access checks by adding _entity_access requirements to several routes in gutenberg.routing.yml and explicitly verifying view access in src/Controller/MediaController.php and src/Service/MediaService.php.
Also in this release Normalised configuration schemas, added the missing core block, and improved UI logic for moving fields and selecting blocks.
config/install/gutenberg.mediaedit.yml+0 −1config/schema/gutenberg.schema.yml+3 −1gutenberg.api.php+28 −0gutenberg.blocks.yml+3 −2gutenberg.install+5 −2gutenberg.module+212 −94gutenberg.post_update.php+61 −0gutenberg.routing.yml+11 −1 fixjs/admin.es6.js+15 −3js/admin.js+10 −3js/drupal-blocks.js+1 −1js/drupal-media.es6.js+1 −1