Description
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2018-3197 Vulnerability (CVE-2018-3197)
IBM WebSEAL Use of Hard-coded Credentials Vulnerability (CVE-2018-1887)
Apache Tomcat Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-12617)
WordPress Plugin RAYS Grid Cross-Site Request Forgery (1.2.2)
WordPress Plugin Accept Donations with PayPal Cross-Site Request Forgery (1.3.3)