Junglewise Threat Intelligence

CVE-2024-13284: DRUPAL-CONTRIB-2024-048 - This module provides a new UI experience for node editing using the Gutenberg Editor library. The module did not sufficiently protect some

CVE-2024-13284 · Severity: info · Published 2024-10-09

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Gutenberg. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module provides a new UI experience for node editing using the Gutenberg Editor library.

The module did not sufficiently protect some routes against a Cross Site Request Forgery attack.

This vulnerability is mitigated by the fact that the tricked user needs to have an active session with the "use gutenberg" permission.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/gutenberg

Related threats