drupal/diff is vulnerable to Access Bypass
50
Medium Risk
The Diff module does not sufficiently restrict access to non-node entity revision diffs, allowing users who can view an entity to access revision differences they should not be able to see. This vulnerability is mitigated by the fact that an attacker must have a role with permission to view the entity.
You are affected if you are using a version that falls within the vulnerable range.
drupal/diff is vulnerable to Access Bypass in versions 0.0.1 - 2.0.0 and 2.1.0 - 2.1.0.
Upgrade the drupal/diff module to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant