CVE Vulnerabilities

CVE-2016-7572

Published: Oct 03, 2016 | Modified: Oct 04, 2016
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for Export configuration permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 8.0.0 (including) 8.0.0 (including)
Drupal Drupal 8.0.0-alpha10 (including) 8.0.0-alpha10 (including)
Drupal Drupal 8.0.0-alpha11 (including) 8.0.0-alpha11 (including)
Drupal Drupal 8.0.0-alpha12 (including) 8.0.0-alpha12 (including)
Drupal Drupal 8.0.0-alpha13 (including) 8.0.0-alpha13 (including)
Drupal Drupal 8.0.0-alpha14 (including) 8.0.0-alpha14 (including)
Drupal Drupal 8.0.0-alpha15 (including) 8.0.0-alpha15 (including)
Drupal Drupal 8.0.0-alpha2 (including) 8.0.0-alpha2 (including)
Drupal Drupal 8.0.0-alpha3 (including) 8.0.0-alpha3 (including)
Drupal Drupal 8.0.0-alpha4 (including) 8.0.0-alpha4 (including)
Drupal Drupal 8.0.0-alpha5 (including) 8.0.0-alpha5 (including)
Drupal Drupal 8.0.0-alpha6 (including) 8.0.0-alpha6 (including)
Drupal Drupal 8.0.0-alpha7 (including) 8.0.0-alpha7 (including)
Drupal Drupal 8.0.0-alpha8 (including) 8.0.0-alpha8 (including)
Drupal Drupal 8.0.0-alpha9 (including) 8.0.0-alpha9 (including)
Drupal Drupal 8.0.0-beta1 (including) 8.0.0-beta1 (including)
Drupal Drupal 8.0.0-beta10 (including) 8.0.0-beta10 (including)
Drupal Drupal 8.0.0-beta11 (including) 8.0.0-beta11 (including)
Drupal Drupal 8.0.0-beta12 (including) 8.0.0-beta12 (including)
Drupal Drupal 8.0.0-beta13 (including) 8.0.0-beta13 (including)
Drupal Drupal 8.0.0-beta14 (including) 8.0.0-beta14 (including)
Drupal Drupal 8.0.0-beta15 (including) 8.0.0-beta15 (including)
Drupal Drupal 8.0.0-beta16 (including) 8.0.0-beta16 (including)
Drupal Drupal 8.0.0-beta2 (including) 8.0.0-beta2 (including)
Drupal Drupal 8.0.0-beta3 (including) 8.0.0-beta3 (including)
Drupal Drupal 8.0.0-beta4 (including) 8.0.0-beta4 (including)
Drupal Drupal 8.0.0-beta6 (including) 8.0.0-beta6 (including)
Drupal Drupal 8.0.0-beta7 (including) 8.0.0-beta7 (including)
Drupal Drupal 8.0.0-beta9 (including) 8.0.0-beta9 (including)
Drupal Drupal 8.0.0-rc1 (including) 8.0.0-rc1 (including)
Drupal Drupal 8.0.0-rc2 (including) 8.0.0-rc2 (including)
Drupal Drupal 8.0.0-rc3 (including) 8.0.0-rc3 (including)
Drupal Drupal 8.0.0-rc4 (including) 8.0.0-rc4 (including)
Drupal Drupal 8.0.1 (including) 8.0.1 (including)
Drupal Drupal 8.0.2 (including) 8.0.2 (including)
Drupal Drupal 8.0.3 (including) 8.0.3 (including)
Drupal Drupal 8.0.4 (including) 8.0.4 (including)
Drupal Drupal 8.0.5 (including) 8.0.5 (including)
Drupal Drupal 8.0.6 (including) 8.0.6 (including)
Drupal Drupal 8.1.0 (including) 8.1.0 (including)
Drupal Drupal 8.1.0-beta1 (including) 8.1.0-beta1 (including)
Drupal Drupal 8.1.0-beta2 (including) 8.1.0-beta2 (including)
Drupal Drupal 8.1.0-rc1 (including) 8.1.0-rc1 (including)
Drupal Drupal 8.1.1 (including) 8.1.1 (including)
Drupal Drupal 8.1.2 (including) 8.1.2 (including)
Drupal Drupal 8.1.3 (including) 8.1.3 (including)
Drupal Drupal 8.1.4 (including) 8.1.4 (including)
Drupal Drupal 8.1.5 (including) 8.1.5 (including)
Drupal Drupal 8.1.6 (including) 8.1.6 (including)
Drupal Drupal 8.1.7 (including) 8.1.7 (including)
Drupal Drupal 8.1.8 (including) 8.1.8 (including)
Drupal Drupal 8.1.9 (including) 8.1.9 (including)
Drupal6 Ubuntu precise *
Drupal7 Ubuntu precise *
Drupal7 Ubuntu yakkety *

References