Shorthand - Critical - Access bypass - SA-CONTRIB-2023-038
View online: https://www.drupal.org/sa-contrib-2023-038 Project: Shorthand [1] Version: 4.0.24.0.14.0.0 Date: 2023-August-23 Security risk: *Critical* 15∕25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <4.0.3 Description: This module provides integration with Shorthand, an application which describes itself as "beautifully simple storytelling". The module does not check appropriate permissions when displaying a list of all shorthand stories. Solution: Install the latest version: * If you use the Shorthand module for Drupal 8+, upgrade to Shorthand 4.0.3 [3] Reported By: * Paul Martin [4] Fixed By: * Vladimir Roudakov [5] Coordinated By: * Damien McKenna [6] of the Drupal Security Team * Dave Long [7] of the Drupal Security Team * Greg Knaddison [8] of the Drupal Security Team [1] https://www.drupal.org/project/shorthand [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/shorthand/releases/4.0.3 [4] https://www.drupal.org/user/2221576 [5] https://www.drupal.org/user/673120 [6] https://www.drupal.org/user/108450 [7] https://www.drupal.org/user/246492 [8] https://www.drupal.org/user/36762
participants (1)
-
security-news@drupal.org