Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-6377

Опубликовано: 16 мар. 2017
Источник: debian

Описание

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal8itppackage

Примечания

  • https://www.drupal.org/SA-2017-001

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

CVSS3: 7.5
nvd
больше 8 лет назад

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

CVSS3: 7.5
github
около 3 лет назад

Drupal editor module incorrectly checks access to inline private files