⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2017-6922Files or Directories Accessible to External Parties in Drupal Core

Severity
6.5MEDIUMNVD
EPSS
1.8%
top 17.22%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 22
Latest updateMay 13

Description

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload file

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Packagistdrupal/core7.07.56+1
CVEListV5drupal/drupal_coreDrupal 88.3.3+1
NVDdrupal/drupal7.07.56+1
Packagistdrupal/drupal8.08.3.4+1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

5
OSV
Drupal core access bypass vulnerability2022-05-13
GHSA
Drupal core access bypass vulnerability2022-05-13
CVEList
Files uploaded by anonymous users into a private file system can be accessed by other anonymous users2019-01-22
OSV
CVE-2017-6922: In Drupal core 82019-01-22
VulnCheck
Drupal Drupal Core Files or Directories Accessible to External Parties2017

💬Community

3
Bugzilla
CVE-2017-6922 drupal7: Files uploaded by anonymous users into a private file system can be accessed by other anonymous users [epel-all]2017-06-22
Bugzilla
CVE-2017-6922 drupal7: Files uploaded by anonymous users into a private file system can be accessed by other anonymous users [fedora-all]2017-06-22
Bugzilla
CVE-2017-6922 drupal7: Files uploaded by anonymous users into a private file system can be accessed by other anonymous users2017-06-22
CVE-2017-6922 — Drupal Core vulnerability | cvebase