Vulnerability DRUPAL-CONTRIB-2019-068

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
7 years ago
September 25, 2019 at 02:43 PM UTC
No summary available

Details

This module enables you to control access to content based on taxonomy terms. The module doesn't sufficiently check if a given entity should be access controlled, defaulting to allowing access even to unpublished nodes.

The vulnerability is mitigated by the fact that the submodule Permissions by Entity must also be enabled.

Timeline

Published
7 years ago
September 25, 2019 at 02:43 PM UTC
Last Modified
28 days ago
September 10, 2026 at 03:45 AM UTC