user_entityforms not secured with permissions or access restriction

Created on 6 August 2018, over 6 years ago
Updated 20 January 2023, almost 2 years ago

The user_entityforms view that ships with the module does not use access restrictions of any kind to secure the data.

There is a filter on the view that maps the logged in user to the data, and this seems adequate to hide results from public view... but it probably isn't.

The view relies on security through obscurity which at the very least means it will trip any security audit checking for unsecured views (which is how this issue came to light for me).

🐛 Bug report
Status

Fixed

Version

2.0

Component

Code

Created by

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

  • views

    Involves, uses, or integrates with views. In Drupal 8 core, use the “VDC” tag instead.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

No activities found.

Production build 0.71.5 2024