CVE Vulnerabilities

CVE-2016-7572

Published: Oct 03, 2016 | Modified: Apr 12, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for Export configuration permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal8.0.0 (including)8.0.0 (including)
DrupalDrupal8.0.0-alpha10 (including)8.0.0-alpha10 (including)
DrupalDrupal8.0.0-alpha11 (including)8.0.0-alpha11 (including)
DrupalDrupal8.0.0-alpha12 (including)8.0.0-alpha12 (including)
DrupalDrupal8.0.0-alpha13 (including)8.0.0-alpha13 (including)
DrupalDrupal8.0.0-alpha14 (including)8.0.0-alpha14 (including)
DrupalDrupal8.0.0-alpha15 (including)8.0.0-alpha15 (including)
DrupalDrupal8.0.0-alpha2 (including)8.0.0-alpha2 (including)
DrupalDrupal8.0.0-alpha3 (including)8.0.0-alpha3 (including)
DrupalDrupal8.0.0-alpha4 (including)8.0.0-alpha4 (including)
DrupalDrupal8.0.0-alpha5 (including)8.0.0-alpha5 (including)
DrupalDrupal8.0.0-alpha6 (including)8.0.0-alpha6 (including)
DrupalDrupal8.0.0-alpha7 (including)8.0.0-alpha7 (including)
DrupalDrupal8.0.0-alpha8 (including)8.0.0-alpha8 (including)
DrupalDrupal8.0.0-alpha9 (including)8.0.0-alpha9 (including)
DrupalDrupal8.0.0-beta1 (including)8.0.0-beta1 (including)
DrupalDrupal8.0.0-beta10 (including)8.0.0-beta10 (including)
DrupalDrupal8.0.0-beta11 (including)8.0.0-beta11 (including)
DrupalDrupal8.0.0-beta12 (including)8.0.0-beta12 (including)
DrupalDrupal8.0.0-beta13 (including)8.0.0-beta13 (including)
DrupalDrupal8.0.0-beta14 (including)8.0.0-beta14 (including)
DrupalDrupal8.0.0-beta15 (including)8.0.0-beta15 (including)
DrupalDrupal8.0.0-beta16 (including)8.0.0-beta16 (including)
DrupalDrupal8.0.0-beta2 (including)8.0.0-beta2 (including)
DrupalDrupal8.0.0-beta3 (including)8.0.0-beta3 (including)
DrupalDrupal8.0.0-beta4 (including)8.0.0-beta4 (including)
DrupalDrupal8.0.0-beta6 (including)8.0.0-beta6 (including)
DrupalDrupal8.0.0-beta7 (including)8.0.0-beta7 (including)
DrupalDrupal8.0.0-beta9 (including)8.0.0-beta9 (including)
DrupalDrupal8.0.0-rc1 (including)8.0.0-rc1 (including)
DrupalDrupal8.0.0-rc2 (including)8.0.0-rc2 (including)
DrupalDrupal8.0.0-rc3 (including)8.0.0-rc3 (including)
DrupalDrupal8.0.0-rc4 (including)8.0.0-rc4 (including)
DrupalDrupal8.0.1 (including)8.0.1 (including)
DrupalDrupal8.0.2 (including)8.0.2 (including)
DrupalDrupal8.0.3 (including)8.0.3 (including)
DrupalDrupal8.0.4 (including)8.0.4 (including)
DrupalDrupal8.0.5 (including)8.0.5 (including)
DrupalDrupal8.0.6 (including)8.0.6 (including)
DrupalDrupal8.1.0 (including)8.1.0 (including)
DrupalDrupal8.1.0-beta1 (including)8.1.0-beta1 (including)
DrupalDrupal8.1.0-beta2 (including)8.1.0-beta2 (including)
DrupalDrupal8.1.0-rc1 (including)8.1.0-rc1 (including)
DrupalDrupal8.1.1 (including)8.1.1 (including)
DrupalDrupal8.1.2 (including)8.1.2 (including)
DrupalDrupal8.1.3 (including)8.1.3 (including)
DrupalDrupal8.1.4 (including)8.1.4 (including)
DrupalDrupal8.1.5 (including)8.1.5 (including)
DrupalDrupal8.1.6 (including)8.1.6 (including)
DrupalDrupal8.1.7 (including)8.1.7 (including)
DrupalDrupal8.1.8 (including)8.1.8 (including)
DrupalDrupal8.1.9 (including)8.1.9 (including)
Drupal6Ubuntuprecise*
Drupal7Ubuntuprecise*
Drupal7Ubuntuyakkety*

References