{"id":"DRUPAL-CONTRIB-2024-007","details":"The Entity Delete Log module tracks the deletion of configured entity types, such as node or comments.\n\nIt does not add sufficient permission to the log report page, allowing an attacker to view information from deleted entities.","aliases":["CVE-2024-13243"],"modified":"2026-09-10T03:45:47.551876460Z","published":"2024-01-31T17:22:36Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2024-007"}],"affected":[{"package":{"name":"drupal/entity_delete_log","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/entity_delete_log?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1"}],"database_specific":{"constraint":"\u003c1.1.1"}}],"database_specific":{"affected_versions":"\u003c1.1.1","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/entity_delete_log/DRUPAL-CONTRIB-2024-007.json"}}],"schema_version":"1.9.0","credits":[{"name":"Ryan Szrama","contact":["https://www.drupal.org/user/49344"]}]}