7.5

CVE-2017-6377

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

Data is provided by the National Vulnerability Database (NVD)
DrupalDrupal Version8.2.0
DrupalDrupal Version8.2.0 Updatebeta1
DrupalDrupal Version8.2.0 Updatebeta2
DrupalDrupal Version8.2.0 Updatebeta3
DrupalDrupal Version8.2.0 Updaterc1
DrupalDrupal Version8.2.0 Updaterc2
DrupalDrupal Version8.2.1
DrupalDrupal Version8.2.2
DrupalDrupal Version8.2.3
DrupalDrupal Version8.2.4
DrupalDrupal Version8.2.5
DrupalDrupal Version8.2.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.26% 0.464
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.