Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58f3-cx8p-h8jg

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Drupal core access bypass vulnerability

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.56

7.56

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.3.4

8.3.4

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.3.4

8.3.4

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.56

7.56

EPSS

Процентиль: 74%
0.0085
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system.

CVSS3: 6.5
nvd
больше 6 лет назад

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system.

CVSS3: 6.5
debian
больше 6 лет назад

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; P ...

EPSS

Процентиль: 74%
0.0085
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-552