Vulnerability Bulletins

Drupal Core - Critical - Access Bypass - SA-CORE-2017-002

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2017-002Project: Drupal core Version: 8.xDate: 2017-April-19 CVEID: CVE-2017-6919Security risk: 17/25 ( Critical) AC:Basic/A:User/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: Access bypassDescriptionThis is a critical access bypass vulnerability. A site is only affected by this if all of the following conditions are met:The site has the RESTful Web Services (rest) module enabled.The site allows PATCH requests.An attacker can get or register a user account on

More info:

https://www.drupal.org/SA-CORE-2017-002