Description
Drupal Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to bypass certain security restrictions and perform otherwise restricted actions. Drupal Core version 8.8.0 is vulnerable.
Remediation
Update to Drupal Core version 8.8.1 or latest
References
Related Vulnerabilities
WeBid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3815)
PHP Out-of-bounds Read Vulnerability (CVE-2019-11041)
Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-3814)
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2019-10097)
WordPress Plugin Really Simple Gallery Multiple Vulnerabilities (1.4)