Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfh2-7f6h-3m85

Опубликовано: 24 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Access bypass in Drupal Core

Drupal core form API evaluates form element access incorrectly. This can lead to a user being able to alter data they should not have access to.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.0.0, < 9.3.19

9.3.19

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 9.4.0, < 9.4.3

9.4.3

EPSS

Процентиль: 52%
0.00284
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data they should not have access to. No forms provided by Drupal core are known to be vulnerable. However, forms added through contributed or custom modules or themes may be affected.

CVSS3: 6.5
nvd
около 2 лет назад

Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user being able to alter data they should not have access to. No forms provided by Drupal core are known to be vulnerable. However, forms added through contributed or custom modules or themes may be affected.

CVSS3: 6.5
debian
около 2 лет назад

Under certain circumstances, the Drupal core form API evaluates form e ...

EPSS

Процентиль: 52%
0.00284
Низкий

6.5 Medium

CVSS3