Vulnerability Name: | CVE-2017-6925 (CCN-130574) | ||||||||||||
Assigned: | 2017-08-16 | ||||||||||||
Published: | 2017-08-16 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs, and entities that have different access restrictions on different revisions of the same entity. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-6925 Source: CCN Type: IBM Security Bulletin 2008323 (API Connect) API Connect Portal is affected by multiple Drupal vulnerabilities Source: CCN Type: IBM Security Bulletin 2008902 (API Connect) API Connect Portal is affected by multiple Drupal vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 100368 Source: CCN Type: BID-100368 Drupal Core DRUPAL-SA-CORE-2017-004 Multiple Access Bypass Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039200 Source: XF Type: UNKNOWN drupal-cve20176925-sec-bypas(130574) Source: CONFIRM Type: Mitigation, Vendor Advisory https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiple Source: CCN Type: DRUPAL-SA-CORE-2017-004 Drupal Core - Multiple Vulnerabilities Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-6925 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |