Node View Permissions
A visitor without an account could read private pieces of content that belonged to deleted users. They could see this hidden information. They could not change or delete anything on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a user account was cancelled and their private pieces of content were reassigned to visitors without an account.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Node View Permissions to 8.x-1.7 or 2.0.1, whichever branch you are on.
For developers: what the fix changed
The fix updates the node_view_permissions_node_grants function in node_view_permissions.module to ensure that the account ID is not zero before granting view own content permissions, preventing anonymous users from accessing reassigned private content.
node_view_permissions.module+3 −2 fix