Role Delegation - Moderately critical - Privilege escalation - SA-CONTRIB-2022-031

Project: Role DelegationDate: 2022-March-23Security risk: Moderately critical 14∕25 AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:DefaultVulnerability: Privilege escalationDescription: This module allows site administrators to grant specific roles the authority to assign selected roles to users, without them needing the administer permissions permission.
The module contains an access bypass vulnerability when used in combination with the Views Bulk Operations module. An authenticated user is able to assign the administrator role to his own user.
This vulnerability is mitigated by the fact that an attacker must have access to an overview of users with the views bulk operations module enabled. E.g. The admin_views module provides such a view. Solution: Install the latest version:

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2022-031