CVE Database
/

CVE-2017-6377

Back to search

CVE-2017-6377

Published: Mar 16, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

VendorProductVersions

Drupal

Drupal Core

affected
8.2.x versions before 8.2.7

References

1038058
vdb-entry
x_refsource_SECTRACK
96919
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now