{"id":"DRUPAL-CONTRIB-2017-083","details":"Custom Permissions is a lightweight module that allows permissions to be created and managed through an administrative form.\n\nWhen this module is in use, any user who is able to perform an action which rebuilds some of Drupal's caches can trigger a scenario in which certain pages protected by this module's custom permissions temporarily lose those custom access controls, thereby leading to an access bypass vulnerability.","modified":"2026-09-10T03:45:25.448118747Z","published":"2017-11-08T17:22:08Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2017-083"}],"affected":[{"package":{"name":"drupal/config_perms","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/config_perms?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.0"}],"database_specific":{"constraint":"\u003c1.1.0"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/config_perms/DRUPAL-CONTRIB-2017-083.json","affected_versions":"\u003c1.1.0"}}],"schema_version":"1.9.0","credits":[{"name":"David Rothstein","contact":["https://www.drupal.org/user/124982"]},{"name":"Michael Koza","contact":["https://www.drupal.org/user/2110062"]}]}