{"id":"DRUPAL-CONTRIB-2018-071","details":"This module enables you to resolve the provided Drupal path in order to find the canonical path and information about the resolved entity. This information includes entity type ID, entity ID, entity UUID and entity label.\n\nThe module doesn't sufficiently check access before displaying entity labels. This leads to the display of labels on entities that are not be accessible, for example; titles of unpublished content.","modified":"2026-09-10T03:45:13.678873835Z","published":"2018-10-31T14:59:17Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2018-071"}],"affected":[{"package":{"name":"drupal/decoupled_router","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/decoupled_router?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.0"}],"database_specific":{"constraint":"\u003c1.2.0"}}],"database_specific":{"affected_versions":"\u003c1.2.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/decoupled_router/DRUPAL-CONTRIB-2018-071.json"}}],"schema_version":"1.9.0","credits":[{"name":"Rainer Friederich","contact":["https://www.drupal.org/user/3066367"]}]}