Description
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
Remediation
References
Related Vulnerabilities
Jboss EAP Improper Input Validation Vulnerability (CVE-2010-1871)
Jenkins Incorrect Authorization Vulnerability (CVE-2021-21670)
WordPress Plugin youForms for WordPress-Creating Forms for CopeCart Cross-Site Scripting (1.0.5)
WordPress Plugin Woocommerce Product Designer Arbitrary File Upload (3.0.3)