CVE-2017-6377

HIGH7.5EPSS 0.29%

Drupal editor module incorrectly checks access to inline private files

Published: 5/13/2022Modified: 4/23/2024

Description

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (7)