Key auth
The module does not store pages separately for each user when caching is turned on. A user with an ordinary account could see the security keys belonging to another user with the same access rights to read private information and change some data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if the dynamic page cache module is turned on.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Key auth to 2.2.4.
For developers: what the fix changed
The fix updates src/Form/UserKeyAuthForm.php to explicitly add per user caching to the access results in buildForm and checkAccess.
Also in this release Added a test for view only key access.
src/Form/UserKeyAuthForm.php+20 −13 fix