restrict_route_by_ipThis module enables you to restrict access to routes by IP address.
The module doesn't reliably restrict a subset of dynamic routes, leading to an access bypass vulnerability. The impact depends on how a site uses this module and whether it has any routes that are dynamic.
Install the latest version:
- If you use the Restrict route by IP 2.0.x, upgrade to Restrict route by IP 2.0.1
- If you use the Restrict route by IP 1.3.x, upgrade to Restrict route by IP 1.3.1
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team