After upgrading a site for a client (engineeringventures.com) to Drupal core v.7.37, I discovered this notice from the administration section:
Dynamic display block 7.x-1.0
Project not supported: This project is no longer supported, and is no longer available for download. Disabling everything included by this project is strongly recommended!
And the information from the project page informs me:
This module is unsupported due to a security issue the maintainer didn’t fix. See Dynamic display block - Less Critical - Access bypass - Unsupported - SA-CONTRIB-2015-104 for details.
If you want to use this module, your options are:
- Choose another, actively maintained module instead
- File an issue in the queue with a patch to fix the module and then contact the security team to have your version reviewed and the project handed over to you following the unsupported project process.
- Hire someone to fix the security bug so the module can be re-published (see this guide on how to hire a Drupal site developer)
Do you plan to fix the module? Or do we proceed with option 2 here?
P.S. I'm not sure what specific 7.x version (dev, rc1 or beta1) since this information doesn't seem to be in any of the TXT documents in the module folder. Please let me know if I can get you any other helpful information.
Comments
Comment #1
edminn commentedComment #2
edminn commentedComment #3
edminn commentedComment #4
ppblaauw commentedThe module will be fixed soon.
Comment #5
roball commentedFirst thing to do is to review the patches for D7 and D6 at #2484591: Enforce node access permissions - SA-CONTRIB-2015-104 if the solve SA-CONTRIB-2015-104.
Comment #6
ppblaauw commentedPosted patches on the original issue
Comment #7
edminn commentedWhich patches? It's not clear from the thread.
Comment #8
ppblaauw commentedsee: https://www.drupal.org/node/2484591