#VU10703 Security restrictions bypass in Drupal - CVE-2017-6930
Published: February 22, 2018 / Updated: March 23, 2018
Drupal
Drupal
Description
The weakness exists due to incorrect language fallback on multilingual sites with node access restrictions. A remote attacker can bypass access.
The issue only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().