4.3

CVE-2016-7572

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Drupal Version 8.0.0
Drupal ≫ Drupal Version 8.0.0 Update alpha10
Drupal ≫ Drupal Version 8.0.0 Update alpha11
Drupal ≫ Drupal Version 8.0.0 Update alpha12
Drupal ≫ Drupal Version 8.0.0 Update alpha13
Drupal ≫ Drupal Version 8.0.0 Update alpha14
Drupal ≫ Drupal Version 8.0.0 Update alpha15
Drupal ≫ Drupal Version 8.0.0 Update alpha2
Drupal ≫ Drupal Version 8.0.0 Update alpha3
Drupal ≫ Drupal Version 8.0.0 Update alpha4
Drupal ≫ Drupal Version 8.0.0 Update alpha5
Drupal ≫ Drupal Version 8.0.0 Update alpha6
Drupal ≫ Drupal Version 8.0.0 Update alpha7
Drupal ≫ Drupal Version 8.0.0 Update alpha8
Drupal ≫ Drupal Version 8.0.0 Update alpha9
Drupal ≫ Drupal Version 8.0.0 Update beta1
Drupal ≫ Drupal Version 8.0.0 Update beta10
Drupal ≫ Drupal Version 8.0.0 Update beta11
Drupal ≫ Drupal Version 8.0.0 Update beta12
Drupal ≫ Drupal Version 8.0.0 Update beta13
Drupal ≫ Drupal Version 8.0.0 Update beta14
Drupal ≫ Drupal Version 8.0.0 Update beta15
Drupal ≫ Drupal Version 8.0.0 Update beta16
Drupal ≫ Drupal Version 8.0.0 Update beta2
Drupal ≫ Drupal Version 8.0.0 Update beta3
Drupal ≫ Drupal Version 8.0.0 Update beta4
Drupal ≫ Drupal Version 8.0.0 Update beta6
Drupal ≫ Drupal Version 8.0.0 Update beta7
Drupal ≫ Drupal Version 8.0.0 Update beta9
Drupal ≫ Drupal Version 8.0.0 Update rc1
Drupal ≫ Drupal Version 8.0.0 Update rc2
Drupal ≫ Drupal Version 8.0.0 Update rc3
Drupal ≫ Drupal Version 8.0.0 Update rc4
Drupal ≫ Drupal Version 8.0.1
Drupal ≫ Drupal Version 8.0.2
Drupal ≫ Drupal Version 8.0.3
Drupal ≫ Drupal Version 8.0.4
Drupal ≫ Drupal Version 8.0.5
Drupal ≫ Drupal Version 8.0.6
Drupal ≫ Drupal Version 8.1.0
Drupal ≫ Drupal Version 8.1.0 Update beta1
Drupal ≫ Drupal Version 8.1.0 Update beta2
Drupal ≫ Drupal Version 8.1.0 Update rc1
Drupal ≫ Drupal Version 8.1.1
Drupal ≫ Drupal Version 8.1.2
Drupal ≫ Drupal Version 8.1.3
Drupal ≫ Drupal Version 8.1.4
Drupal ≫ Drupal Version 8.1.5
Drupal ≫ Drupal Version 8.1.6
Drupal ≫ Drupal Version 8.1.7
Drupal ≫ Drupal Version 8.1.8
Drupal ≫ Drupal Version 8.1.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.72% 0.744
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/93101
Third Party Advisory
http://www.securitytracker.com/id/1036886
Third Party Advisory
https://www.drupal.org/SA-CORE-2016-004
Vendor Advisory