CVE-2017-6928Incorrect Permission Assignment in Drupal

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 48.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 13

Description

Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which one module is trying to grant access to the file and another is trying to deny it, leading to an access bypass vulnerability. This vulnerability is mitigated by the fact that it only occurs for unusual site configurations.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages4 packages

Packagistdrupal/core7.07.57
CVEListV5drupal.org/drupal_coreDrupal 7.x versions before 7.57
NVDdrupal/drupal7.07.57
Packagistdrupal/drupal7.07.57

Also affects: Debian Linux 7.0, 8.0, 9.0

🔴Vulnerability Details

4
OSV
Drupal access bypass vulnerability2022-05-13
GHSA
Drupal access bypass vulnerability2022-05-13
CVEList
CVE-2017-6928: Drupal core 72018-03-01
OSV
CVE-2017-6928: Drupal core 72018-03-01

📋Vendor Advisories

1
Drupal
Drupal core - Critical - Multiple Vulnerabilities - SA-CORE-2018-0012018-02-21

💬Community

4
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001)2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal8: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
CVE-2017-6928 — Incorrect Permission Assignment | cvebase