Description
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2987)
WordPress Plugin WordPress Download Manager Remote Code Execution (2.7.4)
WordPress Plugin N-Media Website Contact Form with File Upload Arbitrary File Upload (1.3.4)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4588)