CVE-2017-6924
published 2019-01-15CVE-2017-6924: In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does…
PriorityP346high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
EPSS
2.10%
79.4th percentile
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | core | >= 8.0 < 8.3.7 | 8.3.7 |
| drupal | drupal | >= 8.0 < 8.3.7 | 8.3.7 |
| drupal | drupal | >= 8.0.0 < 8.3.7 | 8.3.7 |
| drupal | drupal_core | >= Drupal 8 < 8.3.7 | 8.3.7 |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Drupal REST API can bypass comment approval
ghsa·2022-05-13
CVE-2017-6924 [HIGH] CWE-269 Drupal REST API can bypass comment approval
Drupal REST API can bypass comment approval
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments.
OSV
Drupal REST API can bypass comment approval
osv·2022-05-13
CVE-2017-6924 [HIGH] Drupal REST API can bypass comment approval
Drupal REST API can bypass comment approval
In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6923 CVE-2017-6924 CVE-2017-6925 drupal8: Multiple Vulnerabilities - SA-CORE-2017-004 [fedora-all]
bugzilla·2017-08-22·CVSS 6.5
CVE-2017-6923 [MEDIUM] CVE-2017-6923 CVE-2017-6924 CVE-2017-6925 drupal8: Multiple Vulnerabilities - SA-CORE-2017-004 [fedora-all]
CVE-2017-6923 CVE-2017-6924 CVE-2017-6925 drupal8: Multiple Vulnerabilities - SA-CORE-2017-004 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2017-6923 CVE-2017-6924 CVE-2017-6925 drupal8: Multiple Vulnerabilities - SA-CORE-2017-004
bugzilla·2017-08-22·CVSS 6.5
CVE-2017-6923 [MEDIUM] CVE-2017-6923 CVE-2017-6924 CVE-2017-6925 drupal8: Multiple Vulnerabilities - SA-CORE-2017-004
CVE-2017-6923 CVE-2017-6924 CVE-2017-6925 drupal8: Multiple Vulnerabilities - SA-CORE-2017-004
Follwowing vulnerabilities have been addressed in Drupal 8.3.7:
* Views - Access Bypass - Moderately Critical - Drupal 8 - CVE-2017-6923:
When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is mitigated if you have access restrictions on the view.
It is best practice to always include some form of access restrictions on all views, even if you are using another module to display them.
* REST API can bypass comment approval - Access Bypass - Moderately Critical - Drupal 8 - CVE-2017-6924:
When using the REST API, users without the
http://www.securityfocus.com/bid/100368http://www.securitytracker.com/id/1039200https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiplehttp://www.securityfocus.com/bid/100368http://www.securitytracker.com/id/1039200https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-08-16/drupal-core-multiple
2019-01-15
Published