CVE-2017-6919

All FrameworksDrupalCWE-OtherCVE-2017-6919

CVE-2017-6919

State: PUBLISHED · Published: 2017-04-20 · Updated: 2024-08-05 · Assigner: drupal
Description
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2017/6xxx/CVE-2017-6919.json