Entity Delete Log – Moderately critical – Access bypass – SA-CONTRIB-2024-007

Drupal Security Advisory

Date: 
2024-January-31
Vulnerability: 
Access bypass
Affected versions: 
<1.1.1
Description: 

The Entity Delete Log module tracks the deletion of configured entity types, such as node or comments.

It does not add sufficient permission to the log report page, allowing an attacker to view information from deleted entities.

Solution: 

Install the latest version:

Note: This release updates the default permissions for the entity_delete_log view. After the update, you may want to review that permission if you already changed it from the default.

Reported By: 
Coordinated By: 

READ MORE