← Back

CVE-2017-6377

nvd nist
Published: Mar 16, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

Affected (12)

Products: Drupal: Drupal
1 product
Drupal
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
Version 8.2.0
Version 8.2.0 beta1
Version 8.2.0 beta2
Version 8.2.0 beta3
Version 8.2.0 rc1
Version 8.2.0 rc2
Version 8.2.1
Version 8.2.2
Version 8.2.3
Version 8.2.4
Version 8.2.5
Version 8.2.6

References (6)

Source: mlhess@drupal.org
Third Party AdvisoryVDB Entry
Source: mlhess@drupal.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.