{"id":"DRUPAL-CONTRIB-2023-001","details":"This module enables users to create 'private' vocabularies.\n\nThe module doesn't enforce permissions appropriately for the taxonomy overview page and overview form.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with the permission \"Administer own taxonomy\" or \"View private taxonomies\"","modified":"2026-09-10T03:45:34.551464606Z","published":"2023-01-11T17:15:37Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2023-001"}],"affected":[{"package":{"name":"drupal/private_taxonomy","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/private_taxonomy?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0"}],"database_specific":{"constraint":"\u003c2.6.0"}}],"database_specific":{"affected_versions":"\u003c2.6.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/private_taxonomy/DRUPAL-CONTRIB-2023-001.json"}}],"schema_version":"1.9.0","credits":[{"name":"Giuseppe","contact":["https://www.drupal.org/user/3521392"]}]}