Vulnerability Name: | CVE-2017-6924 (CCN-130573) | ||||||||||||
Assigned: | 2017-08-16 | ||||||||||||
Published: | 2017-08-16 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments. | ||||||||||||
CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-269 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-6924 Source: CCN Type: IBM Security Bulletin 2008323 (API Connect) API Connect Portal is affected by multiple Drupal vulnerabilities Source: CCN Type: IBM Security Bulletin 2008902 (API Connect) API Connect Portal is affected by multiple Drupal vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 100368 Source: CCN Type: BID-100368 Drupal Core DRUPAL-SA-CORE-2017-004 Multiple Access Bypass Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039200 Source: XF Type: UNKNOWN drupal-cve20176924-sec-bypas(130573) Source: CONFIRM Type: Mitigation, Vendor Advisory https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiple Source: CCN Type: DRUPAL-SA-CORE-2017-004 Drupal Core - Multiple Vulnerabilities Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-6924 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |