Vulnerability Name: | CVE-2017-6923 (CCN-130559) | ||||||||||||
Assigned: | 2017-08-16 | ||||||||||||
Published: | 2017-08-16 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is mitigated if you have access restrictions on the view. It is best practice to always include some form of access restrictions on all views, even if you are using another module to display them. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-862 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-6923 Source: CCN Type: IBM Security Bulletin 2008323 (API Connect) API Connect Portal is affected by multiple Drupal vulnerabilities Source: CCN Type: IBM Security Bulletin 2008902 (API Connect) API Connect Portal is affected by multiple Drupal vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 100368 Source: CCN Type: BID-100368 Drupal Core DRUPAL-SA-CORE-2017-004 Multiple Access Bypass Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039200 Source: XF Type: UNKNOWN drupal-cve20176923-sec-bypas(130559) Source: CONFIRM Type: Patch, Release Notes, Vendor Advisory https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiple Source: CCN Type: DRUPAL-SA-CORE-2017-004 Drupal Core - Multiple Vulnerabilities Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-6923 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |