Project:
Date:
2021-July-28
Vulnerability:
Access bypass
Affected versions:
<1.4.0
Description:
This project enables administrators to restrict access from anonymous and regular users to pre-defined pages.
The administration routes used by the project lacked proper permissions, allowing untrusted users to access, create and modify the module's settings.
Solution:
Install the latest version:
- If you use the Pages Restriction Access for Drupal 8.x, upgrade to Pages Restriction Access for Drupal 8.x-1.4
Reported By:
Fixed By:
Coordinated By:
- Chris McCafferty of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team