Authentication Bypass Affecting drupal/drupal package, versions >=8.0, <8.3.7


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-DRUPALDRUPAL-70092
  • published16 Aug 2017
  • disclosed16 Aug 2017
  • creditMaxim Podorov

Introduced: 16 Aug 2017

CVE-2017-6923  (opens in a new tab)
CWE-592  (opens in a new tab)

How to fix?

Upgrade drupal/drupal to version 8.3.7 or higher.

Overview

Affected versions of drupal/drupal are vulnerable to Authentication Bypass.

When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is mitigated if you have access restrictions on the view.

CVSS Scores

version 3.1