Логотип exploitDog
bind:CVE-2017-6930
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-6930

Количество 3

Количество 3

nvd логотип

CVE-2017-6930

больше 7 лет назад

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2017-6930

больше 7 лет назад

In Drupal versions 8.4.x versions before 8.4.5 when using node access ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3327-jr93-7hq3

около 3 лет назад

Drupal access bypass vulnerability

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-6930

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().

CVSS3: 8.1
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-6930

In Drupal versions 8.4.x versions before 8.4.5 when using node access ...

CVSS3: 8.1
0%
Низкий
больше 7 лет назад
github логотип
GHSA-3327-jr93-7hq3

Drupal access bypass vulnerability

CVSS3: 8.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу