This vulnerability is mitigated by three factors:
- The JSON:API or REST File upload modules must be enabled on the site.
- An attacker must have access to a file upload via JSON:API or REST.
- The site must employ a file validation module.
This advisory is not covered by Drupal Steward.
Also see GraphQL – Moderately critical – Access bypass – SA-CONTRIB-2021-029 which addresses a similar vulnerability for that module.
- If you are using Drupal 9.2, update to Drupal 9.2.6.
- If you are using Drupal 9.1, update to Drupal 9.1.13.
- If you are using Drupal 8.9, update to Drupal 8.9.19.
Versions of Drupal 8 prior to 8.9.x and versions of Drupal 9 prior to 9.1.x are end-of-life and do not receive security coverage.
Drupal 7 core is not affected.
Go to Source