Access Restriction Bypass Affecting drupal/core package, versions >=8.0, <8.3.7
Snyk CVSS
Attack Complexity
Low
Threat Intelligence
EPSS
0.95% (84th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-DRUPALCORE-70064
- published 16 Aug 2017
- disclosed 16 Aug 2017
- credit Unknown
Introduced: 16 Aug 2017
CVE-2017-6924 Open this link in a new tabHow to fix?
Upgrade drupal/core
to version 8.3.7 or higher.
Overview
Affected versions of drupal/core
are vulnerable to Access Restriction Bypass.
When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments.