{"id":"DRUPAL-CONTRIB-2023-037","details":"This module enables you to build administrative pages for managing configuration objects, which may then be used elsewhere in the site.\n\nThe module doesn't sufficiently validate access when the JSONAPI module is also installed.\n\nThis vulnerability is mitigated by the fact that it only affects sites when the JSONAPI module is installed.","modified":"2026-09-10T03:45:26.765742481Z","published":"2023-08-23T16:54:32Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2023-037"}],"affected":[{"package":{"name":"drupal/config_pages","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/config_pages?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.0"}],"database_specific":{"constraint":"\u003c2.9.0"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/config_pages/DRUPAL-CONTRIB-2023-037.json","affected_versions":"\u003c2.9.0"}}],"schema_version":"1.9.0","credits":[{"name":"Nate Andersen","contact":["https://www.drupal.org/user/471638"]}]}