CVE Vulnerabilities

CVE-2017-6919

Published: Apr 20, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal8.0.0 (including)8.0.0 (including)
DrupalDrupal8.0.0-alpha10 (including)8.0.0-alpha10 (including)
DrupalDrupal8.0.0-alpha11 (including)8.0.0-alpha11 (including)
DrupalDrupal8.0.0-alpha12 (including)8.0.0-alpha12 (including)
DrupalDrupal8.0.0-alpha13 (including)8.0.0-alpha13 (including)
DrupalDrupal8.0.0-alpha14 (including)8.0.0-alpha14 (including)
DrupalDrupal8.0.0-alpha15 (including)8.0.0-alpha15 (including)
DrupalDrupal8.0.0-alpha2 (including)8.0.0-alpha2 (including)
DrupalDrupal8.0.0-alpha3 (including)8.0.0-alpha3 (including)
DrupalDrupal8.0.0-alpha4 (including)8.0.0-alpha4 (including)
DrupalDrupal8.0.0-alpha5 (including)8.0.0-alpha5 (including)
DrupalDrupal8.0.0-alpha6 (including)8.0.0-alpha6 (including)
DrupalDrupal8.0.0-alpha7 (including)8.0.0-alpha7 (including)
DrupalDrupal8.0.0-alpha8 (including)8.0.0-alpha8 (including)
DrupalDrupal8.0.0-alpha9 (including)8.0.0-alpha9 (including)
DrupalDrupal8.0.0-beta1 (including)8.0.0-beta1 (including)
DrupalDrupal8.0.0-beta10 (including)8.0.0-beta10 (including)
DrupalDrupal8.0.0-beta11 (including)8.0.0-beta11 (including)
DrupalDrupal8.0.0-beta12 (including)8.0.0-beta12 (including)
DrupalDrupal8.0.0-beta13 (including)8.0.0-beta13 (including)
DrupalDrupal8.0.0-beta14 (including)8.0.0-beta14 (including)
DrupalDrupal8.0.0-beta15 (including)8.0.0-beta15 (including)
DrupalDrupal8.0.0-beta16 (including)8.0.0-beta16 (including)
DrupalDrupal8.0.0-beta2 (including)8.0.0-beta2 (including)
DrupalDrupal8.0.0-beta3 (including)8.0.0-beta3 (including)
DrupalDrupal8.0.0-beta4 (including)8.0.0-beta4 (including)
DrupalDrupal8.0.0-beta6 (including)8.0.0-beta6 (including)
DrupalDrupal8.0.0-beta7 (including)8.0.0-beta7 (including)
DrupalDrupal8.0.0-beta9 (including)8.0.0-beta9 (including)
DrupalDrupal8.0.0-rc1 (including)8.0.0-rc1 (including)
DrupalDrupal8.0.0-rc2 (including)8.0.0-rc2 (including)
DrupalDrupal8.0.0-rc3 (including)8.0.0-rc3 (including)
DrupalDrupal8.0.0-rc4 (including)8.0.0-rc4 (including)
DrupalDrupal8.0.1 (including)8.0.1 (including)
DrupalDrupal8.0.2 (including)8.0.2 (including)
DrupalDrupal8.0.3 (including)8.0.3 (including)
DrupalDrupal8.0.4 (including)8.0.4 (including)
DrupalDrupal8.0.5 (including)8.0.5 (including)
DrupalDrupal8.0.6 (including)8.0.6 (including)
DrupalDrupal8.1.0 (including)8.1.0 (including)
DrupalDrupal8.1.0-beta1 (including)8.1.0-beta1 (including)
DrupalDrupal8.1.0-beta2 (including)8.1.0-beta2 (including)
DrupalDrupal8.1.0-rc1 (including)8.1.0-rc1 (including)
DrupalDrupal8.1.1 (including)8.1.1 (including)
DrupalDrupal8.1.2 (including)8.1.2 (including)
DrupalDrupal8.1.3 (including)8.1.3 (including)
DrupalDrupal8.1.4 (including)8.1.4 (including)
DrupalDrupal8.1.5 (including)8.1.5 (including)
DrupalDrupal8.1.6 (including)8.1.6 (including)
DrupalDrupal8.1.7 (including)8.1.7 (including)
DrupalDrupal8.1.8 (including)8.1.8 (including)
DrupalDrupal8.1.9 (including)8.1.9 (including)
DrupalDrupal8.1.10 (including)8.1.10 (including)
DrupalDrupal8.2.0 (including)8.2.0 (including)
DrupalDrupal8.2.0-beta1 (including)8.2.0-beta1 (including)
DrupalDrupal8.2.0-beta2 (including)8.2.0-beta2 (including)
DrupalDrupal8.2.0-beta3 (including)8.2.0-beta3 (including)
DrupalDrupal8.2.0-rc1 (including)8.2.0-rc1 (including)
DrupalDrupal8.2.0-rc2 (including)8.2.0-rc2 (including)
DrupalDrupal8.2.1 (including)8.2.1 (including)
DrupalDrupal8.2.2 (including)8.2.2 (including)
DrupalDrupal8.2.3 (including)8.2.3 (including)
DrupalDrupal8.2.4 (including)8.2.4 (including)
DrupalDrupal8.2.5 (including)8.2.5 (including)
DrupalDrupal8.2.6 (including)8.2.6 (including)
DrupalDrupal8.2.7 (including)8.2.7 (including)
DrupalDrupal8.3.0 (including)8.3.0 (including)
DrupalDrupal8.3.0-alpha1 (including)8.3.0-alpha1 (including)
DrupalDrupal8.3.0-beta1 (including)8.3.0-beta1 (including)
DrupalDrupal8.3.0-rc1 (including)8.3.0-rc1 (including)
DrupalDrupal8.3.0-rc2 (including)8.3.0-rc2 (including)

References