In certain configuration cases, when a learning path is configured as semi-private, anonymous users are allowed to join a learning path when they should not.
Install the latest version:
- If you use the opigno learning path module for Drupal 8.x, upgrade to opigno_learning_path 8.x-1.4
- If using the opigno lms distribution it is recommended to update the whole distribution to the latest version Opigno lms 8.x-1.5
Also see the Opigno Learning path project page.
- Nathaniel Catchpole of the Drupal Security Team
- James Aparicio
- Nathaniel Catchpole of the Drupal Security Team
- Nathaniel Catchpole of the Drupal Security Team