Описание
Drupal File upload access bypass and denial of service
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-3162
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2016-3162.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2016-3162.yaml
- https://www.drupal.org/SA-CORE-2016-001
- http://www.debian.org/security/2016/dsa-3498
- http://www.openwall.com/lists/oss-security/2016/02/24/19
- http://www.openwall.com/lists/oss-security/2016/03/15/10
Пакеты
drupal/core
>= 7.0, < 7.43
7.43
drupal/core
>= 8.0, < 8.0.4
8.0.4
drupal/drupal
>= 8.0, < 8.0.4
8.0.4
drupal/drupal
>= 7.0, < 7.43
7.43
Связанные уязвимости
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows ...