CVE Vulnerabilities

CVE-2016-7570

Published: Oct 03, 2016 | Modified: Apr 12, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Drupal 8.x before 8.1.10 does not properly check for Administer comments permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal8.0.0 (including)8.0.0 (including)
DrupalDrupal8.0.0-alpha10 (including)8.0.0-alpha10 (including)
DrupalDrupal8.0.0-alpha11 (including)8.0.0-alpha11 (including)
DrupalDrupal8.0.0-alpha12 (including)8.0.0-alpha12 (including)
DrupalDrupal8.0.0-alpha13 (including)8.0.0-alpha13 (including)
DrupalDrupal8.0.0-alpha14 (including)8.0.0-alpha14 (including)
DrupalDrupal8.0.0-alpha15 (including)8.0.0-alpha15 (including)
DrupalDrupal8.0.0-alpha2 (including)8.0.0-alpha2 (including)
DrupalDrupal8.0.0-alpha3 (including)8.0.0-alpha3 (including)
DrupalDrupal8.0.0-alpha4 (including)8.0.0-alpha4 (including)
DrupalDrupal8.0.0-alpha5 (including)8.0.0-alpha5 (including)
DrupalDrupal8.0.0-alpha6 (including)8.0.0-alpha6 (including)
DrupalDrupal8.0.0-alpha7 (including)8.0.0-alpha7 (including)
DrupalDrupal8.0.0-alpha8 (including)8.0.0-alpha8 (including)
DrupalDrupal8.0.0-alpha9 (including)8.0.0-alpha9 (including)
DrupalDrupal8.0.0-beta1 (including)8.0.0-beta1 (including)
DrupalDrupal8.0.0-beta10 (including)8.0.0-beta10 (including)
DrupalDrupal8.0.0-beta11 (including)8.0.0-beta11 (including)
DrupalDrupal8.0.0-beta12 (including)8.0.0-beta12 (including)
DrupalDrupal8.0.0-beta13 (including)8.0.0-beta13 (including)
DrupalDrupal8.0.0-beta14 (including)8.0.0-beta14 (including)
DrupalDrupal8.0.0-beta15 (including)8.0.0-beta15 (including)
DrupalDrupal8.0.0-beta16 (including)8.0.0-beta16 (including)
DrupalDrupal8.0.0-beta2 (including)8.0.0-beta2 (including)
DrupalDrupal8.0.0-beta3 (including)8.0.0-beta3 (including)
DrupalDrupal8.0.0-beta4 (including)8.0.0-beta4 (including)
DrupalDrupal8.0.0-beta6 (including)8.0.0-beta6 (including)
DrupalDrupal8.0.0-beta7 (including)8.0.0-beta7 (including)
DrupalDrupal8.0.0-beta9 (including)8.0.0-beta9 (including)
DrupalDrupal8.0.0-rc1 (including)8.0.0-rc1 (including)
DrupalDrupal8.0.0-rc2 (including)8.0.0-rc2 (including)
DrupalDrupal8.0.0-rc3 (including)8.0.0-rc3 (including)
DrupalDrupal8.0.0-rc4 (including)8.0.0-rc4 (including)
DrupalDrupal8.0.1 (including)8.0.1 (including)
DrupalDrupal8.0.2 (including)8.0.2 (including)
DrupalDrupal8.0.3 (including)8.0.3 (including)
DrupalDrupal8.0.4 (including)8.0.4 (including)
DrupalDrupal8.0.5 (including)8.0.5 (including)
DrupalDrupal8.0.6 (including)8.0.6 (including)
DrupalDrupal8.1.0 (including)8.1.0 (including)
DrupalDrupal8.1.0-beta1 (including)8.1.0-beta1 (including)
DrupalDrupal8.1.0-beta2 (including)8.1.0-beta2 (including)
DrupalDrupal8.1.0-rc1 (including)8.1.0-rc1 (including)
DrupalDrupal8.1.1 (including)8.1.1 (including)
DrupalDrupal8.1.2 (including)8.1.2 (including)
DrupalDrupal8.1.3 (including)8.1.3 (including)
DrupalDrupal8.1.4 (including)8.1.4 (including)
DrupalDrupal8.1.5 (including)8.1.5 (including)
DrupalDrupal8.1.6 (including)8.1.6 (including)
DrupalDrupal8.1.7 (including)8.1.7 (including)
DrupalDrupal8.1.8 (including)8.1.8 (including)
DrupalDrupal8.1.9 (including)8.1.9 (including)
Drupal6Ubuntuprecise*
Drupal7Ubuntuprecise*
Drupal7Ubuntuyakkety*

References