2.1 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:H/Au:S/C:P/I:N/A:N
0.967 High
EPSS
Percentile
99.7%
This module enables you to make configuration options generally available only at the sitewide level to be configurable and overridden by individual “spaces” on a Drupal site.
The spaces submodule, Spaces OG, doesn’t properly handle deleting of organic group group spaces when the option to move to a new group is selected. Instead of moving the content to a new group, the content is left orphaned, and for deleted private groups, that content will then be viewable by anyone with “access content” permission when the site’s or content’s access is rebuilt.
The issue is mitigated by needing to be using the submodule spaces OG, and needing the site users to be in the situation of deleting a group and using that move option, and needing the content’s access to be rebuilt.
Drupal core is not affected. If you do not use the contributed Spaces module, there is nothing you need to do.
Install the latest version:
Also see the Spaces project page.