Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmqh-2j2x-vgp3

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Drupal Unprivileged access to config export

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.1.10

8.1.10

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 8.0, < 8.1.10

8.1.10

EPSS

Процентиль: 57%
0.00352
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 8 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

CVSS3: 4.3
nvd
больше 8 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

CVSS3: 4.3
debian
больше 8 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not proper ...

EPSS

Процентиль: 57%
0.00352
Низкий

4.3 Medium

CVSS3