{"id":"DRUPAL-CONTRIB-2024-004","details":"Content within Open Social can have different visibilities. It is possible for a user to create public content even when this should not be allowed.  \nThis vulnerability is mitigated by the fact that the site must have public visibility disabled on a global level.","aliases":["CVE-2024-13240"],"modified":"2026-03-18T18:00:07.404950Z","published":"2024-01-24T15:45:49Z","withdrawn":"2026-03-18T18:00:07.404950Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-004"}],"affected":[{"package":{"name":"drupal/social","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/social"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.0.5"}],"database_specific":{"constraint":"\u003c12.0.5"}}],"database_specific":{"affected_versions":"\u003c12.0.5","patched":true,"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/social/DRUPAL-CONTRIB-2024-004.json"}}],"schema_version":"1.7.3","credits":[{"name":"Corn696","contact":["https://www.drupal.org/user/3544002"]}]}