Date: 
Saturday, Oct 29th, 2022
Advisory ID: 
BACKDROP-SA-CORE-2022-008
Security risk: 
Moderately Critical
Vulnerability: 
Access bypass
Versions affected: 
Description: 

Rate module provides flexible voting widgets for nodes and comments.

Rate module did not sufficiently check access for nodes and comments.

Solution: 

Upgrade your site to the most recent version of Rate module. Download available on the Rate module 1.x-1.0.1 release page

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  • Log in to backdropcms.org
  • Edit your profile
  • Scroll down to the "Email notifications" section
  • Check the box labeled "Receive BackdropCMS.org security announcements for core and contrib projects"