Vulnerability from drupal
Published
2025-08-13 17:33
Modified
2025-09-03 18:53
Summary
Details
The Layout Builder Advanced Permissions module enables you to have fine grained control over who can do what in editing pages built with Layout Builder.
The module doesn't sufficiently control access for adding sections in the submodule.
This vulnerability is mitigated by the fact that an attacker must have a role with a specific set of permissions:
- Node: View published content
- Node: (Your content type): Create new content
- Node: (Your content type): Edit any content
- Layout builder: (Your content type): Configure layout overrides for content items that the user can edit
- Layout builder advanced permissions: Access Layout Builder page
Credits
Eelke Blok (eelkeblok)
www.drupal.org/u/eelkeblok
Michael Whittaker (mrwhittaker)
www.drupal.org/u/mrwhittaker
{
"affected": [
{
"database_specific": {
"affected_versions": "2.2.0"
},
"package": {
"ecosystem": "Packagist:https://packages.drupal.org/8",
"name": "drupal/layout_builder_perms"
},
"ranges": [
{
"database_specific": {
"constraint": "2.2.0"
},
"events": [
{
"introduced": "2.2.0"
},
{
"last_affected": "2.2.0"
}
],
"type": "ECOSYSTEM"
}
],
"severity": []
}
],
"aliases": [
"CVE-2025-8996"
],
"credits": [
{
"contact": [
"https://www.drupal.org/u/eelkeblok"
],
"name": "Eelke Blok (eelkeblok)"
},
{
"contact": [
"https://www.drupal.org/u/mrwhittaker"
],
"name": "Michael Whittaker (mrwhittaker)"
}
],
"details": "The Layout Builder Advanced Permissions module enables you to have fine grained control over who can do what in editing pages built with Layout Builder.\n\nThe module doesn\u0027t sufficiently control access for adding sections in the submodule.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with a specific set of permissions:\n\n* Node: View published content\n* Node: (Your content type): Create new content\n* Node: (Your content type): Edit any content\n* Layout builder: (Your content type): Configure layout overrides for content items that the user can edit\n* Layout builder advanced permissions: Access Layout Builder page",
"id": "DRUPAL-CONTRIB-2025-097",
"modified": "2025-09-03T18:53:10.000Z",
"published": "2025-08-13T17:33:34.000Z",
"references": [
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2025-097"
}
],
"schema_version": "1.7.0"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…