5
CVSSv2

CVE-2017-6377

Published: 16/03/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

When adding a private file via the editor in Drupal 8.2.x prior to 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 8.2.0

drupal drupal 8.2.4

drupal drupal 8.2.5

drupal drupal 8.2.2

drupal drupal 8.2.3

drupal drupal 8.2.6

drupal drupal 8.2.1