Project: 
Version: 
8.8.x-dev
8.7.x-dev
Date: 
2019-December-18
Vulnerability: 
Access bypass
Description: 
The Media Library module has a security vulnerability whereby it doesn't sufficiently restrict access to media items in certain configurations.
Solution: 
- If you are using Drupal 8.7.x, you should upgrade to Drupal 8.7.11.
 - If you are using Drupal 8.8.x, you should upgrade to Drupal 8.8.1.
 
Versions of Drupal 8 prior to 8.7.x are end-of-life and do not receive security coverage.
Alternatively, you may mitigate this vulnerability by unchecking the "Enable advanced UI" checkbox on /admin/config/media/media-library. (This mitigation is not available in 8.7.x.)
Additional information
All advisories released today:
Updating to the latest Drupal core release will apply the fixes for all the above advisories.
Reported By: 
Fixed By: 
- Adam G-H
 - Jess of the Drupal Security Team
 - Andrei Mateescu
 - Greg Knaddison of the Drupal Security Team
 - Alex Bronstein of the Drupal Security Team
 - Sean Blommaert
 - Lee Rowlands of the Drupal Security Team