Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-7572

Опубликовано: 03 окт. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 4.3

Описание

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

РелизСтатусПримечание
artful

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

devel

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

not-affected

precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

not-affected

trusty/esm

not-affected

upstream

needs-triage

vivid/stable-phone-overlay

DNE

Показывать по

EPSS

Процентиль: 57%
0.00352
Низкий

4 Medium

CVSS2

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 8 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

CVSS3: 4.3
debian
больше 8 лет назад

The system.temporary route in Drupal 8.x before 8.1.10 does not proper ...

CVSS3: 4.3
github
около 3 лет назад

Drupal Unprivileged access to config export

EPSS

Процентиль: 57%
0.00352
Низкий

4 Medium

CVSS2

4.3 Medium

CVSS3

Уязвимость CVE-2016-7572