← Back

CVE-2017-6379

nvd nist
Published: Mar 16, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

Affected (12)

Products: Drupal: Drupal
1 product
Drupal
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
Version 8.2.0
Version 8.2.0 beta1
Version 8.2.0 beta2
Version 8.2.0 beta3
Version 8.2.0 rc1
Version 8.2.0 rc2
Version 8.2.1
Version 8.2.2
Version 8.2.3
Version 8.2.4
Version 8.2.5
Version 8.2.6

References (6)

Source: mlhess@drupal.org
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory

Timeline

No history available yet.