This module enables you to add key-based authentication on a per-user
basis.
The module doesn't cache per user, potentially allowing an attacker to view another user's authentication keys, if the attacker has the same permissions.
This vulnerability is mitigated by the fact that the site must have the dynamic_page_cache module enabled.
Install the latest version:
- If you use the Key Auth module, upgrade to Key auth 2.2.4.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team