Project:
Date:
2018-August-29
Security risk:
Vulnerability:
Access bypass
Affected versions:
<2.9.0
Description:
This module enables you to build eCommerce websites and applications with Drupal.
The module doesn't sufficiently check access for some of its entity types.
Solution:
Update to Commerce 8.x-2.9.
Reported By:
- Samuel Mortenson of the Drupal Security Team
Fixed By:
- Samuel Mortenson of the Drupal Security Team
- Matt Glaman
- Bojan Živanović
- Wim Leers
Coordinated By:
- Samuel Mortenson of the Drupal Security Team