Vulnerability Description
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | 8.2.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96919Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038058
- https://www.drupal.org/SA-2017-001Vendor Advisory
- http://www.securityfocus.com/bid/96919Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038058
- https://www.drupal.org/SA-2017-001Vendor Advisory
FAQ
What is CVE-2017-6377?
CVE-2017-6377 is a vulnerability with a CVSS score of 7.5 (HIGH). When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
How severe is CVE-2017-6377?
CVE-2017-6377 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6377?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal.