fac 8.x-1.8

Security update
Bug fixes

This release fixes a security vulnerability where a malicious user could be able to read search results generated by users with other roles, disclosing search results the user normally has no access to. This vulnerability could only be exploited when the configuration option "Perform search as anonymous user only" is switched off.

See SA-CONTRIB-2021-005 for details.

If your configuration enables searches as authenticated users we urge you to update the module to this release.

Pages

Subscribe with RSS Subscribe to RSS - Security update