Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmqh-2j2x-vgp3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Drupal Unprivileged access to config export

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.1.10

8.1.10

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.1.10

8.1.10

EPSS

Процентиль: 56%
0.00344
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 9 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

CVSS3: 4.3
nvd
почти 9 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

CVSS3: 4.3
debian
почти 9 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not proper ...

EPSS

Процентиль: 56%
0.00344
Низкий

4.3 Medium

CVSS3