Open Social - Moderately critical - Access bypass - SA-CONTRIB-2024-076

Few notes to take into account:

  • This release contains an update hook that can possibly create new folders. Make sure to run the hook as the correct user or via update.php so it has the correct owner.
  • The update hook does not take unmanaged/unorphaned files into account. In usual cases these should be cleaned up automatically by cron when they are not set temporary. To verify this there are a few option to take:
    1. Use the files overview to identify and remove affected files.
    2. Temporary enable the contrib module https://www.drupal.org/project/fancy_file_delete which provides an additional view and bulk operations.
    3. Run database queries.
VCS Label
12.3.10
Packaged Git sha1
462040351f86563f953a875b55c3cfe7a3cf8c53
Release files
2bc34cf9f330848f119f89a7568a2658
Release file SHA-1 hash
20c8aea622bac19bc2bae0e3e55155d304501fbe
Release file SHA-256 hash
c458a5b952d3bf9f62ca0c9ffbbdb1403bb1f150551eb436fe63ab3b00bee0a7
35093e9a12a89080c1776ffff502feae
Release file SHA-1 hash
eee420ba1ff7ae741d028ba4bc859c2fde441710
Release file SHA-256 hash
d75f2edfa5e009272037773ea1ed0e5bdd12bb0f7fd9a281a6c58cc454a491a9