Field Collection - Moderately Critical - Access Bypass
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-1.3
The Field Collection module granted users with the "edit field collections" permission unconditional access to field collection items, bypassing parent entity access checks entirely. A separate flaw allowed access when the host entity could not be loaded, as passing NULL to "entity_access()" may return TRUE for some entity types.