Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated with existing permissions, resulting in some possible access bypass for users who have access to use revisions of content generally, but who do not have access to individual items of node and media content. This vulnerability only affects sites using Drupal’s revision system.
More Stories
uriparser-0.9.8-2.el8
FEDORA-EPEL-2025-1f39c6fc05 Packages in this update: uriparser-0.9.8-2.el8 Update description: Update to uriparser-0.9.8. Read More
uriparser-0.9.8-2.el10_1
FEDORA-EPEL-2025-7b4e3ab4cf Packages in this update: uriparser-0.9.8-2.el10_1 Update description: Update to uriparser-0.9.8. Read More
uriparser-0.9.8-2.el9
FEDORA-EPEL-2025-e9dcb51f6d Packages in this update: uriparser-0.9.8-2.el9 Update description: Update to uriparser-0.9.8. Read More
qgis-3.42.1-2.fc42
FEDORA-2025-f12c63c177 Packages in this update: qgis-3.42.1-2.fc42 Update description: Fix CVE-2024-55565. Update to 3.42.1. Update to qgis-3.42.0 Read More
qgis-3.40.5-2.fc41
FEDORA-2025-ccb6313749 Packages in this update: qgis-3.40.5-2.fc41 Update description: Fix CVE-2024-55565. Update to 3.40.5. Update to 3.40.4. Read More
mingw-libxslt-1.1.43-1.fc42
FEDORA-2025-8603e39722 Packages in this update: mingw-libxslt-1.1.43-1.fc42 Update description: Update to 1.1.43, fixes CVE-2024-55549 and CVE-2025-24855. Read More