Role Delegation
A user who is allowed to assign basic roles could give themselves the main administrator role. This would let them see all private data and change anything on the website. They could not do this if they only had a standard user account.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the site uses the Views Bulk Operations module and the user can see a list of users.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Role Delegation to 8.x-1.5.
For developers: what the fix changed
The release diff is linked below. No summary of the fix has been written for this one.
README.md+24 −41role_delegation.api.php+23 −0role_delegation.module+5 −11role_delegation.services.yml+2 −1src/Access/RoleDelegationAccessCheck.php+18 −12src/DelegatableRoles.php+23 −1src/DelegatableRolesInterface.php+1 −1src/Form/RoleDelegationSettingsForm.php+1 −1src/Plugin/Action/RoleDelegationAddRoleUser.php+1 −48src/Plugin/Action/RoleDelegationManagerRoleUserTrait.php+77 −0src/Plugin/Action/RoleDelegationRemoveRoleUser.php+1 −48