DRUPAL-CONTRIB-2022-016
Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2022-016
DRUPAL-CONTRIB-2022-016
Summary:
Details: **Update** Maintainers stepped forward, fixed the security issue, and Vocabulary Permissions Per Role is supported again. The module allows adding to/editing terms of/removing terms from vocabularies per role. The module did not properly check access for certain operations allowing an unauthorized malicious user to view, modify and delete terms. **Original advisory** The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: <https://www.drupal.org/node/251466#procedure---own-project---unsupported>
References: https://www.drupal.org/sa-contrib-2022-016
Affected packages
Package
Name: drupal/vppr
Purl: pkg:composer/drupal/vppr?repository_url=https:%2F%2Fpackages.drupal.org%2F8
Affected ranges
Type: ECOSYSTEM
Events:
