View online: https://www.drupal.org/sa-contrib-2023-038
Project: Shorthand [1] Version: 4.0.24.0.14.0.0 Date: 2023-August-23 Security risk: *Critical* 15∕25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass
Affected versions: <4.0.3 Description: This module provides integration with Shorthand, an application which describes itself as "beautifully simple storytelling".
The module does not check appropriate permissions when displaying a list of all shorthand stories.
Solution: Install the latest version:
* If you use the Shorthand module for Drupal 8+, upgrade to Shorthand 4.0.3 [3]
Reported By: * Paul Martin [4]
Fixed By: * Vladimir Roudakov [5]
Coordinated By: * Damien McKenna [6] of the Drupal Security Team * Dave Long [7] of the Drupal Security Team * Greg Knaddison [8] of the Drupal Security Team
[1] https://www.drupal.org/project/shorthand [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/shorthand/releases/4.0.3 [4] https://www.drupal.org/user/2221576 [5] https://www.drupal.org/user/673120 [6] https://www.drupal.org/user/108450 [7] https://www.drupal.org/user/246492 [8] https://www.drupal.org/user/36762