{"id":"DRUPAL-CONTRIB-2018-081","details":"This module provides a JSON:API specification-compliant HTTP API for accessing and manipulating Drupal content and configuration entities.\n\nThe module doesn't sufficiently check access when responding to certain filtered collection requests, thereby causing an access bypass vulnerability. (This means certain `GET` requests are vulnerable; no `POST`, `PATCH` or `DELETE` requests are vulnerable.)\n\nIn order to fix this issue, two new hooks were added: `hook_jsonapi_ENTITY_TYPE_filter_access()` and `hook_jsonapi_entity_field_filter_access()`. Sites with custom entity types and/or with entity or field access customizations may need to implement these newly introduced hooks.","modified":"2026-09-10T03:46:02.217251522Z","published":"2018-12-19T17:53:49Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2018-081"}],"affected":[{"package":{"name":"drupal/jsonapi","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/jsonapi?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.24.0"}],"database_specific":{"constraint":"\u003c1.24.0"}}],"database_specific":{"affected_versions":"\u003c1.24.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/jsonapi/DRUPAL-CONTRIB-2018-081.json"}}],"schema_version":"1.9.0","credits":[{"name":"Gabe Sullice","contact":["https://www.drupal.org/user/2287430"]},{"name":"Lauri Eskola","contact":["https://www.drupal.org/user/1078742"]}]}