CVE Vulnerabilities

CVE-2016-7572

Published: Oct 03, 2016 | Modified: Oct 04, 2016
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for Export configuration permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 8.0.0 (including) 8.0.0 (including)
Drupal Drupal 8.0.0-alpha10 (including) 8.0.0-alpha10 (including)
Drupal Drupal 8.0.0-alpha11 (including) 8.0.0-alpha11 (including)
Drupal Drupal 8.0.0-alpha12 (including) 8.0.0-alpha12 (including)
Drupal Drupal 8.0.0-alpha13 (including) 8.0.0-alpha13 (including)
Drupal Drupal 8.0.0-alpha14 (including) 8.0.0-alpha14 (including)
Drupal Drupal 8.0.0-alpha15 (including) 8.0.0-alpha15 (including)
Drupal Drupal 8.0.0-alpha2 (including) 8.0.0-alpha2 (including)
Drupal Drupal 8.0.0-alpha3 (including) 8.0.0-alpha3 (including)
Drupal Drupal 8.0.0-alpha4 (including) 8.0.0-alpha4 (including)
Drupal Drupal 8.0.0-alpha5 (including) 8.0.0-alpha5 (including)
Drupal Drupal 8.0.0-alpha6 (including) 8.0.0-alpha6 (including)
Drupal Drupal 8.0.0-alpha7 (including) 8.0.0-alpha7 (including)
Drupal Drupal 8.0.0-alpha8 (including) 8.0.0-alpha8 (including)
Drupal Drupal 8.0.0-alpha9 (including) 8.0.0-alpha9 (including)
Drupal Drupal 8.0.0-beta1 (including) 8.0.0-beta1 (including)
Drupal Drupal 8.0.0-beta10 (including) 8.0.0-beta10 (including)
Drupal Drupal 8.0.0-beta11 (including) 8.0.0-beta11 (including)
Drupal Drupal 8.0.0-beta12 (including) 8.0.0-beta12 (including)
Drupal Drupal 8.0.0-beta13 (including) 8.0.0-beta13 (including)
Drupal Drupal 8.0.0-beta14 (including) 8.0.0-beta14 (including)
Drupal Drupal 8.0.0-beta15 (including) 8.0.0-beta15 (including)
Drupal Drupal 8.0.0-beta16 (including) 8.0.0-beta16 (including)
Drupal Drupal 8.0.0-beta2 (including) 8.0.0-beta2 (including)
Drupal Drupal 8.0.0-beta3 (including) 8.0.0-beta3 (including)
Drupal Drupal 8.0.0-beta4 (including) 8.0.0-beta4 (including)
Drupal Drupal 8.0.0-beta6 (including) 8.0.0-beta6 (including)
Drupal Drupal 8.0.0-beta7 (including) 8.0.0-beta7 (including)
Drupal Drupal 8.0.0-beta9 (including) 8.0.0-beta9 (including)
Drupal Drupal 8.0.0-rc1 (including) 8.0.0-rc1 (including)
Drupal Drupal 8.0.0-rc2 (including) 8.0.0-rc2 (including)
Drupal Drupal 8.0.0-rc3 (including) 8.0.0-rc3 (including)
Drupal Drupal 8.0.0-rc4 (including) 8.0.0-rc4 (including)
Drupal Drupal 8.0.1 (including) 8.0.1 (including)
Drupal Drupal 8.0.2 (including) 8.0.2 (including)
Drupal Drupal 8.0.3 (including) 8.0.3 (including)
Drupal Drupal 8.0.4 (including) 8.0.4 (including)
Drupal Drupal 8.0.5 (including) 8.0.5 (including)
Drupal Drupal 8.0.6 (including) 8.0.6 (including)
Drupal Drupal 8.1.0 (including) 8.1.0 (including)
Drupal Drupal 8.1.0-beta1 (including) 8.1.0-beta1 (including)
Drupal Drupal 8.1.0-beta2 (including) 8.1.0-beta2 (including)
Drupal Drupal 8.1.0-rc1 (including) 8.1.0-rc1 (including)
Drupal Drupal 8.1.1 (including) 8.1.1 (including)
Drupal Drupal 8.1.2 (including) 8.1.2 (including)
Drupal Drupal 8.1.3 (including) 8.1.3 (including)
Drupal Drupal 8.1.4 (including) 8.1.4 (including)
Drupal Drupal 8.1.5 (including) 8.1.5 (including)
Drupal Drupal 8.1.6 (including) 8.1.6 (including)
Drupal Drupal 8.1.7 (including) 8.1.7 (including)
Drupal Drupal 8.1.8 (including) 8.1.8 (including)
Drupal Drupal 8.1.9 (including) 8.1.9 (including)

References