CVE Vulnerabilities

CVE-2017-6919

Published: Apr 20, 2017 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
HIGH

Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.

Affected Software

Name Vendor Start Version End Version
Drupal Drupal 8.0.0 (including) 8.0.0 (including)
Drupal Drupal 8.0.0-alpha10 (including) 8.0.0-alpha10 (including)
Drupal Drupal 8.0.0-alpha11 (including) 8.0.0-alpha11 (including)
Drupal Drupal 8.0.0-alpha12 (including) 8.0.0-alpha12 (including)
Drupal Drupal 8.0.0-alpha13 (including) 8.0.0-alpha13 (including)
Drupal Drupal 8.0.0-alpha14 (including) 8.0.0-alpha14 (including)
Drupal Drupal 8.0.0-alpha15 (including) 8.0.0-alpha15 (including)
Drupal Drupal 8.0.0-alpha2 (including) 8.0.0-alpha2 (including)
Drupal Drupal 8.0.0-alpha3 (including) 8.0.0-alpha3 (including)
Drupal Drupal 8.0.0-alpha4 (including) 8.0.0-alpha4 (including)
Drupal Drupal 8.0.0-alpha5 (including) 8.0.0-alpha5 (including)
Drupal Drupal 8.0.0-alpha6 (including) 8.0.0-alpha6 (including)
Drupal Drupal 8.0.0-alpha7 (including) 8.0.0-alpha7 (including)
Drupal Drupal 8.0.0-alpha8 (including) 8.0.0-alpha8 (including)
Drupal Drupal 8.0.0-alpha9 (including) 8.0.0-alpha9 (including)
Drupal Drupal 8.0.0-beta1 (including) 8.0.0-beta1 (including)
Drupal Drupal 8.0.0-beta10 (including) 8.0.0-beta10 (including)
Drupal Drupal 8.0.0-beta11 (including) 8.0.0-beta11 (including)
Drupal Drupal 8.0.0-beta12 (including) 8.0.0-beta12 (including)
Drupal Drupal 8.0.0-beta13 (including) 8.0.0-beta13 (including)
Drupal Drupal 8.0.0-beta14 (including) 8.0.0-beta14 (including)
Drupal Drupal 8.0.0-beta15 (including) 8.0.0-beta15 (including)
Drupal Drupal 8.0.0-beta16 (including) 8.0.0-beta16 (including)
Drupal Drupal 8.0.0-beta2 (including) 8.0.0-beta2 (including)
Drupal Drupal 8.0.0-beta3 (including) 8.0.0-beta3 (including)
Drupal Drupal 8.0.0-beta4 (including) 8.0.0-beta4 (including)
Drupal Drupal 8.0.0-beta6 (including) 8.0.0-beta6 (including)
Drupal Drupal 8.0.0-beta7 (including) 8.0.0-beta7 (including)
Drupal Drupal 8.0.0-beta9 (including) 8.0.0-beta9 (including)
Drupal Drupal 8.0.0-rc1 (including) 8.0.0-rc1 (including)
Drupal Drupal 8.0.0-rc2 (including) 8.0.0-rc2 (including)
Drupal Drupal 8.0.0-rc3 (including) 8.0.0-rc3 (including)
Drupal Drupal 8.0.0-rc4 (including) 8.0.0-rc4 (including)
Drupal Drupal 8.0.1 (including) 8.0.1 (including)
Drupal Drupal 8.0.2 (including) 8.0.2 (including)
Drupal Drupal 8.0.3 (including) 8.0.3 (including)
Drupal Drupal 8.0.4 (including) 8.0.4 (including)
Drupal Drupal 8.0.5 (including) 8.0.5 (including)
Drupal Drupal 8.0.6 (including) 8.0.6 (including)
Drupal Drupal 8.1.0 (including) 8.1.0 (including)
Drupal Drupal 8.1.0-beta1 (including) 8.1.0-beta1 (including)
Drupal Drupal 8.1.0-beta2 (including) 8.1.0-beta2 (including)
Drupal Drupal 8.1.0-rc1 (including) 8.1.0-rc1 (including)
Drupal Drupal 8.1.1 (including) 8.1.1 (including)
Drupal Drupal 8.1.2 (including) 8.1.2 (including)
Drupal Drupal 8.1.3 (including) 8.1.3 (including)
Drupal Drupal 8.1.4 (including) 8.1.4 (including)
Drupal Drupal 8.1.5 (including) 8.1.5 (including)
Drupal Drupal 8.1.6 (including) 8.1.6 (including)
Drupal Drupal 8.1.7 (including) 8.1.7 (including)
Drupal Drupal 8.1.8 (including) 8.1.8 (including)
Drupal Drupal 8.1.9 (including) 8.1.9 (including)
Drupal Drupal 8.1.10 (including) 8.1.10 (including)
Drupal Drupal 8.2.0 (including) 8.2.0 (including)
Drupal Drupal 8.2.0-beta1 (including) 8.2.0-beta1 (including)
Drupal Drupal 8.2.0-beta2 (including) 8.2.0-beta2 (including)
Drupal Drupal 8.2.0-beta3 (including) 8.2.0-beta3 (including)
Drupal Drupal 8.2.0-rc1 (including) 8.2.0-rc1 (including)
Drupal Drupal 8.2.0-rc2 (including) 8.2.0-rc2 (including)
Drupal Drupal 8.2.1 (including) 8.2.1 (including)
Drupal Drupal 8.2.2 (including) 8.2.2 (including)
Drupal Drupal 8.2.3 (including) 8.2.3 (including)
Drupal Drupal 8.2.4 (including) 8.2.4 (including)
Drupal Drupal 8.2.5 (including) 8.2.5 (including)
Drupal Drupal 8.2.6 (including) 8.2.6 (including)
Drupal Drupal 8.2.7 (including) 8.2.7 (including)
Drupal Drupal 8.3.0 (including) 8.3.0 (including)
Drupal Drupal 8.3.0-alpha1 (including) 8.3.0-alpha1 (including)
Drupal Drupal 8.3.0-beta1 (including) 8.3.0-beta1 (including)
Drupal Drupal 8.3.0-rc1 (including) 8.3.0-rc1 (including)
Drupal Drupal 8.3.0-rc2 (including) 8.3.0-rc2 (including)

References