Taxonomy Term Glossary
The module does not properly check access rights for categories. Anyone visiting the site could see a list of all categories through a data feed including hidden or unpublished ones. They could not change or delete any of this information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Taxonomy Term Glossary to 4.6.0.
For developers: what the fix changed
The fix updates loadGlossaryTerm in src/Controller/TermGlossaryController.php to ensure the requested term belongs to a configured vocabulary. It also modifies buildCachedJsonResponse to only set public cache headers for anonymous users, preventing restricted terms viewed by authenticated users from being cached and served to others.
Also in this release The release also fixes a bug where a hook received the wrong argument, refactors term storage, and adds tests.
.cspell-project-words.txt+1 −0README.md+4 −2src/Controller/TermGlossaryController.php+40 −13 fixsrc/Service/TermGlossaryManager.php+3 −11