ZeroHour

CVE-2017-6919

CVSS 3.0
7.5 high
EPSS
2%p74
Published
()
Modified
Description

Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.

Vendors
drupal
Products
drupal
Ecosystems
Drupal
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.