Project: 
Date: 
2021-May-12
Vulnerability: 
Access bypass
Affected versions: 
<1.12.0
Description: 

This module provides a new UI experience for node editing using the Gutenberg Editor library.

The module did not correctly validate access rules in certain situations allowing anonymous users to delete blocks.

Solution: 

Install the latest version:

  • If you use the Gutenberg module 8.x-1.x, upgrade to 8.x-1.12
  • If you use the Gutenberg module 8.x-2.x, upgrade to 8.x-2.0
  • For roles other than administrator, the "Administer Gutenberg" (8.x-1.x) or the "Use Gutenberg" (8.x-2.x) permission must be given to view and delete reusable blocks.
Coordinated By: