Quick Tabs
A visitor could see hidden or unpublished pieces of content if an administrator had previously added them to a tab. They could view these specific items without the correct access rights. They could not change or delete any of this information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Quick Tabs to 4.3.1.
For developers: what the fix changed
The fix updates `src/Plugin/TabType/BlockContent.php` and `src/Plugin/TabType/NodeContent.php` to strictly require an allowed access result (`isAllowed()`) rather than just checking for a forbidden result (`isForbidden()`) when rendering block plugins and node tabs. It also adds an explicit access check for reusable custom blocks in `BlockContent.php`.
Also in this release The release also replaces the js_cookie dependency with localStorage for tab memory, fixes an issue where inner tab titles were wiped during AJAX loads, and improves cacheability metadata handling.
composer.json+1 −2js/quicktabs.js+12 −15quicktabs.info.yml+0 −1quicktabs.install+5 −6quicktabs.libraries.yml+0 −1src/Controller/QuickTabsController.php+27 −5src/Entity/QuickTabsInstance.php+1 −1src/Form/QuickTabsInstanceEditForm.php+1 −1src/Plugin/TabRenderer/QuickTabs.php+39 −26src/Plugin/TabType/BlockContent.php+34 −8 fixsrc/Plugin/TabType/NodeContent.php+17 −3 fixsrc/Plugin/TabType/QtabsContent.php+17 −1