Project:
Date:
2024-December-04
Vulnerability:
Access bypass
Affected versions:
>=2.0.0 <2.0.3
CVE IDs:
CVE-2024-13302
Description:
Module to restrict access from anonymous and regular users to configured pre-defined pages.
The module does not adequately handle protecting certain types of URLs.
Solution:
Install the latest version:
- If you use the Pages Restriction Access for Drupal 8.x or higher, upgrade to Pages Restriction Access for Drupal 2.0.3
Reported By:
- Pierre Rudloff
- Ivo Van Geertruyen of the Drupal Security Team
Fixed By:
Coordinated By:
- Greg Knaddison of the Drupal Security Team
- Damien McKenna of the Drupal Security Team
- Juraj Nemec of the Drupal Security Team
- Ivo Van Geertruyen of the Drupal Security Team