Access Bypass in Drupal Core Workspaces Module by Drupal
CVE-2020-13667

5.3MEDIUM

Key Information:

Vendor
Drupal
Vendor
CVE Published:
17 May 2021

Summary

The access bypass vulnerability in the Drupal Core Workspaces module allows attackers to view content they shouldn't be able to access, due to insufficient permission checks when switching workspaces. This issue primarily affects sites that have installed the experimental Workspaces module and can result in unauthorized visibility of content before it is intended for public viewing. Proper permissions must be set to mitigate this risk.

Affected Version(s)

Drupal Core 8.8.X < 8.8.10

Drupal Core 8.9.X < 8.9.6

Drupal Core 9.0.X < 9.0.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.