Project:
Date:
2021-May-12
Vulnerability:
Access bypass
Affected versions:
<1.12.0
Description:
This module provides a new UI experience for node editing using the Gutenberg Editor library.
The module did not correctly validate access rules in certain situations allowing anonymous users to delete blocks.
Solution:
Install the latest version:
Reported By:
Fixed By:
Coordinated By:
- Damien McKenna of the Drupal Security Team