Media revision listing is accessible to anonymous users.

Created on 2 January 2024, 6 months ago
Updated 18 January 2024, 5 months ago

Steps to reproduce

  1. Navigate to Media settings ('/admin/config/media/media-settings')
  2. Enable Standalone media URL
  3. Now, view any media from the front end while ensuring that you are logged out.
  4. As a result, the "View" and "Revision" tabs are visible to logged-out or anonymous users.
🐛 Bug report
Status

Fixed

Version

10.2

Component
Media 

Last updated about 1 hour ago

Created by

🇮🇳India uditrawat

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

Sign in to follow issues

Merge Requests

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024