Role Delegation - Moderately critical - Privilege escalation - SA-CONTRIB-2022-031
Project: Role DelegationDate: 2022-March-23Security risk: Moderately critical 14∕25 AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:DefaultVulnerability: Privilege escalationDescription: This module allows site administrators to grant specific roles the authority to assign selected roles to users, without them needing the administer permissions permission.
The module contains an access bypass vulnerability when used in combination with the Views Bulk Operations module. An authenticated user is able to assign the administrator role to his own user.
This vulnerability is mitigated by the fact that an attacker must have access to an overview of users with the views bulk operations module enabled. E.g. The admin_views module provides such a view. Solution: Install the latest version:
- If you use the Role Delegation module for Drupal 7.x, upgrade to Role Delegation 7.x-1.3
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison of the Drupal Security Team