PT-2022-38352 · Packagist · Drupal/Quick Node Clone

Published

2022-05-04

·

Updated

2022-05-04

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The module adds a "Clone" tab to a node. When clicked, a new node is created and fields from the previous node are populated into the new fields. This module supports paragraphs, groups, and other referenced entities.
The module has a vulnerability which allows attackers to bypass the protection to clone any group content with an access check. Users are allowed to copy other group's nodes, and if they do that, the node gets added to groups they don't have access to.
This vulnerability is mitigated by the fact it only affects sites that also use the Groups contributed module.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2022-038

Affected Products

Drupal/Quick Node Clone