Описание
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| drupal8 | itp | package | ||
| drupal7 | not-affected | package |
Примечания
https://www.drupal.org/SA-CORE-2016-005
https://www.openwall.com/lists/oss-security/2016/11/18/8
EPSS
Процентиль: 45%
0.00227
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 9 лет назад
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
CVSS3: 7.5
nvd
около 9 лет назад
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
CVSS3: 7.5
github
больше 3 лет назад
Drupal Incorrect cache context on password reset page
EPSS
Процентиль: 45%
0.00227
Низкий