{"id":"DRUPAL-CONTRIB-2023-007","details":"Thunder is a Drupal distribution for professional publishing. The thunder distribution ships the thunder\\_gqls module which provides a graphql interface.\n\nThe module doesn't sufficiently check access when serving user data via graphql leading to an access bypass vulnerability potentially exposing email addresses.","modified":"2026-03-18T18:00:07.403572Z","published":"2023-03-01T17:11:03Z","withdrawn":"2026-03-18T18:00:07.403572Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2023-007"}],"affected":[{"package":{"name":"drupal/thunder","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/thunder"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.0"},{"fixed":"6.4.6"}],"database_specific":{"constraint":"\u003e=6.4.0 \u003c6.4.6"}},{"type":"ECOSYSTEM","events":[{"introduced":"6.5.0"},{"fixed":"6.5.3"}],"database_specific":{"constraint":"\u003e=6.5.0 \u003c6.5.3"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/thunder/DRUPAL-CONTRIB-2023-007.json","affected_versions":"\u003e=6.4.0 \u003c6.4.6 || \u003e=6.5.0 \u003c6.5.3"}}],"schema_version":"1.7.3","credits":[{"name":"Steffen Schlaer","contact":["https://www.drupal.org/user/324945"]}]}