CVE-2017-6925
Summary
| CVE | CVE-2017-6925 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-15 17:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs, and entities that have different access restrictions on different revisions of the same entity. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Drupal Core DRUPAL-SA-CORE-2017-004 Multiple Access Bypass Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Drupal Core - Multiple Vulnerabilities - SA-CORE-2017-004 | Drupal.org | CONFIRM | www.drupal.org | Mitigation, Vendor Advisory |
| Drupal Access Control Flaws Let Remote Authenticated Users Bypass Security Restrictions on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.