title: Users without "Administer comments" can set comment visibility on nodes they can edit link: https://www.drupal.org/SA-CORE-2016-004 cve: CVE-2016-7570 branches: 8.0.x: time: 2016-09-21 18:39:00 versions: ['>=8.0','<8.1.0'] 8.1.x: time: 2016-09-21 18:39:00 versions: ['>=8.1.0','<8.1.10'] reference: composer://drupal/core
info at phpclasses dot org