Information disclosure in Drupal - CVE-2017-6926
Published: February 22, 2018 / Updated: March 23, 2018
Vulnerability identifier: #VU10699
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6926
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists improper permissions controls in the comment system. A remote attacker permission to post comments can view content and comments he doesn't have access to, and is also able to add comments to this content.
Affected software
Drupal
Fedora
drupal6
drupal7
drupal8
Fedora
drupal6
drupal7
drupal8
How to mitigate CVE-2017-6926
Update to version 8.4.5.
drupal6 - update to 6.38-2.el6
drupal7 - addressed in versions 7.57-1.el6, 7.57-1.el7, 7.57-1.fc26, 7.57-1.fc27, 7.58-1.el6, 7.58-1.el7, 7.58-1.fc26, 7.58-1.fc27, 7.58-1.fc28
drupal8 - addressed in versions 8.3.9-1.fc26, 8.4.6-3.fc27, 8.4.6-3.fc28
drupal7 - addressed in versions 7.57-1.el6, 7.57-1.el7, 7.57-1.fc26, 7.57-1.fc27, 7.58-1.el6, 7.58-1.el7, 7.58-1.fc26, 7.58-1.fc27, 7.58-1.fc28
drupal8 - addressed in versions 8.3.9-1.fc26, 8.4.6-3.fc27, 8.4.6-3.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Drupal
- Fedora 27 update for drupal7
- Fedora 26 update for drupal7
- Fedora EPEL 6 update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora 27 update for drupal7
- Fedora EPEL 7 update for drupal7
- Fedora EPEL 6 update for drupal7
- Fedora 28 update for drupal7
- Fedora 26 update for drupal7
- Fedora 28 update for drupal8
- Fedora 27 update for drupal8
- Fedora 26 update for drupal8
- Fedora EPEL 6 update for drupal6