Description

The Contextual Links module doesn't sufficiently validate the requested contextual links. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access contextual links".

Description source: GitHub Advisory

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory8.0.0 to < 8.5.8 · Fixed in 8.5.8affected
8.6.0 to < 8.6.2 · Fixed in 8.6.2affected

References

3