Security restrictions bypass in Drupal - CVE-2017-6924

 

Security restrictions bypass in Drupal - CVE-2017-6924

Published: August 16, 2017


Vulnerability identifier: #VU7962
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6924
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to views.

The vulnerability exists due to a design error within RESTful Web Services (rest) module. A remote unauthenticated attacker can use REST API functionality to publish comments without approval.

Successful exploitation of the vulnerability may allow an attacker to post unauthorized comments.

Affected software

Drupal
Fedora
drupal8

How to mitigate CVE-2017-6924

Update to version 8.3.7.

drupal8 - addressed in versions 8.3.7-1.fc25, 8.3.7-1.fc26

External References

Related Security Bulletins