If a user has access to APIv4 REST for purposes of creating/updating one kind of record (such as Contribution),
then they may be able to infer implicit information from a related record-type (such as Contact), even if the user lacks
regular access to the Contact.
This vulnerability arises from insufficient security checks in the "write/join" mechanism.
CiviCRM v6.16.3 and earlier
CiviCRM v6.17.0, v6.16.4, v6.10.9 (ESR), and later
Any ONE of the following will mitigate the vulnerability:
- Upgrade to a fixed version of CiviCRM, or...
- Apply the following patch
Coleman Watts of CiviCRM Core Team, Jakub Fidler
