DRUPAL-CONTRIB-2022-016

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/vppr/DRUPAL-CONTRIB-2022-016.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2022-016
Published
2022-01-25T18:39:26Z
Modified
2025-12-10T23:33:45.666388Z
Summary
[none]
Details

Update
Maintainers stepped forward, fixed the security issue, and Vocabulary Permissions Per Role is supported again.

The module allows adding to/editing terms of/removing terms from vocabularies per role.

The module did not properly check access for certain operations allowing an unauthorized malicious user to view, modify and delete terms.

Original advisory
The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466#procedure---own-project---unsupported

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/vppr

Package

Name
drupal/vppr
Purl
pkg:composer/drupal/vppr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.0
Database specific
{
    "constraint": "<1.2.0"
}

Database specific

affected_versions
"<1.2.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/vppr/DRUPAL-CONTRIB-2022-016.json"