DRUPAL-CONTRIB-2022-014

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/private_taxonomy/DRUPAL-CONTRIB-2022-014.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2022-014
Published
2022-01-26T17:18:11Z
Modified
2026-09-10T03:45:33Z
Summary
[none]
Details

This module enables users to create 'private' vocabularies.

The module doesn't sufficiently check user access permissions when attempting to view, edit, or add terms to vocabularies, including vocabularies not managed by the module.

Partial mitigation is available by requiring users have been granted at least "Administer own taxonomy", "Edit own terms in vocabulary_name" or "Delete own terms in vocabulary_name" permissions, however this does not mitigate all known issues.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/private_taxonomy

Package

Name
drupal/private_taxonomy
Purl
pkg:composer/drupal/private_taxonomy?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.5.0
Database specific
Show details
{
    "constraint": "<2.5.0"
}

Database specific

affected_versions
"<2.5.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/private_taxonomy/DRUPAL-CONTRIB-2022-014.json"