Group control for forums - Critical - Access bypass - SA-CONTRIB-2023-008
Project: Group control for forumsDate: 2023-March-01Security risk: Critical 15∕25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: >=2.0.0 <2.0.2Description: This module enables you to associate Forums as Group 1.x content and use Group access permissions.
Previous versions of the module incorrectly set node access on creation, and did not correctly restrict access to lists of forum topics.Solution: Install the latest version:
- If you use the Group control for forums module for Drupal 9.x or 10.x, upgrade to Group control for forums 2.0.2
Reported By:
Fixed By:
Coordinated By:
- Damien McKenna of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team