Description
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
Remediation
References
Related Vulnerabilities
WordPress Plugin LinkedIn by BestWebSoft Cross-Site Scripting (1.0.4)
WordPress Plugin WP-Stats-Dashboard SQL Injection (2.9.4)
WordPress Plugin Media.net Ads Manager Arbitrary File Upload (2.10.13)
WordPress Plugin DMSGuestbook Multiple Remote Vulnerabilities (1.8.0)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)