drupal/config_pages is vulnerable to Access bypass
60
Medium Risk
Affected versions of this package are vulnerable to access bypass due to insufficient enforcement of access control checks. Specifically, the module fails to properly respect the hook_ENTITY_TYPE_access() permissions, allowing unauthorized users to access or manipulate entities they should not have permission to view or modify. This oversight can lead to unintended exposure of data or unauthorized operations.
You are affected if you are using a version that falls within the vulnerable range.
drupal/config_pages is vulnerable to Access bypass in versions 1.0.0 - 2.17.0.
Upgrade the drupal/config_pages library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant