Vulnerability Bulletins |
Drupal Core - Critical - Access Bypass - SA-CORE-2017-002 |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2017-002Project: Drupal core Version: 8.xDate: 2017-April-19 CVEID: CVE-2017-6919Security risk: 17/25 ( Critical) AC:Basic/A:User/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: Access bypassDescriptionThis is a critical access bypass vulnerability. A site is only affected by this if all of the following conditions are met:The site has the RESTful Web Services (rest) module enabled.The site allows PATCH requests.An attacker can get or register a user account on More info: https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-04-19/drupal-core-critical-access-bypass |
|






