Media Library Form API Element - Moderately critical - Information Disclosure - SA-CONTRIB-2023-004
The module module did not properly check entity access in some circumstances. This may have resulted in users with access to edit content seeing metadata about media items they are not authorized to access.
The vulnerability is mitigated by the fact that the inaccessible media will only be visible to users who can already edit content that includes a media reference field.
VCS Label
2.0.6
Release type
Packaged Git sha1
ca3894e2721ee8285542b0e6094d9438bafc9f7b
Release files
53ec01f557c61911c9c83b13c970ac36
Release file SHA-1 hash
2db8dba124482e3f6956fe331bd4e122b9b9fe83
Release file SHA-256 hash
0532a56f1ca964bad1276b262c01f2a545b2be2fbd824cfd1bd06fcaa82c6508
58746627926726c57373b0275b278913
Release file SHA-1 hash
91363cbea0d1895fbf0fbb9640d70fee47775111
Release file SHA-256 hash
bcec2be20aac2a08174be46a6337cb28edc8b52d3228e6528c21de16613a6828