drupal/entity_share is vulnerable to Access Bypass
60
Medium Risk
Affected versions of this package are vulnerable to access bypass: the module provides some default configuration without sufficient access control. This vulnerability is mitigated by the fact that an administrator can add some default access control permission.
You are affected if you are using a version that falls within the vulnerable range.
drupal/entity_share is vulnerable to Access Bypass in versions 1.0.0 - 3.12.0.
Upgrade the drupal/entity_share library to the patch version. For a hotfix without upgrading the module, edit the entity_share_client_entity_import_status view to ensure access permissions are set.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant