Loading HuntDB...

GHSA-qfhg-m6r8-xxpj

GitHub Security Advisory

Incorrect Authorization in Drupal core

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

Affected Packages

Packagist drupal/core
Affected versions: 8.0.0 (fixed in 8.9.19)
Packagist drupal/core
Affected versions: 9.1.0 (fixed in 9.1.13)
Packagist drupal/core
Affected versions: 9.2.0 (fixed in 9.2.6)

Related CVEs

Key Information

GHSA ID
GHSA-qfhg-m6r8-xxpj
Published
February 12, 2022 12:00 AM
Last Modified
February 23, 2022 4:04 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
drupal/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.