CVE-2017-6926Sensitive Information Exposure in Drupal

Severity
8.1HIGHNVD
OSV6.1
EPSS
0.4%
top 41.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 14

Description

In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by the fact that the comment system must be enabled and the attacker must have permission to post comments.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

Packagistdrupal/core8.4.08.4.5+2
NVDdrupal/drupal8.4.08.4.5
Packagistdrupal/drupal8.4.08.4.5+1
CVEListV5drupal.org/drupal_core8.4.x versions before 8.4.5

🔴Vulnerability Details

4
OSV
Drupal Comment reply form allows access to restricted content2022-05-14
GHSA
Drupal Comment reply form allows access to restricted content2022-05-14
CVEList
CVE-2017-6926: In Drupal versions 82018-03-01
OSV
CVE-2017-6926: This security advisory fixes multiple vulnerabilities in both Drupal 7 and Drupal 82018-02-21

📋Vendor Advisories

1
Drupal
Drupal core - Critical - Multiple Vulnerabilities - SA-CORE-2018-0012018-02-21

💬Community

4
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001)2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal8: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
CVE-2017-6926 — Sensitive Information Exposure | cvebase