CVE-2017-6924
Summary
| CVE | CVE-2017-6924 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-15 20:29:00 UTC |
| Updated | 2023-11-07 02:49:00 UTC |
| Description | In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Drupal Core DRUPAL-SA-CORE-2017-004 Multiple Access Bypass Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-004 | Drupal.org | CONFIRM | www.drupal.org | Mitigation, Vendor Advisory |
| Drupal Access Control Flaws Let Remote Authenticated Users Bypass Security Restrictions on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.