CVE-2017-6930Improper Access Control in Drupal

Severity
8.1HIGHNVD
EPSS
0.4%
top 37.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 13

Description

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Dom

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

Packagistdrupal/core8.4.08.4.5
NVDdrupal/drupal8.4.08.4.5
Packagistdrupal/drupal8.4.08.4.5
CVEListV5drupal.org/drupal_core8.4.x versions before 8.4.5

🔴Vulnerability Details

3
GHSA
Drupal access bypass vulnerability2022-05-13
OSV
Drupal access bypass vulnerability2022-05-13
CVEList
CVE-2017-6930: In Drupal versions 82018-03-01

📋Vendor Advisories

1
Drupal
Drupal core - Critical - Multiple Vulnerabilities - SA-CORE-2018-0012018-02-21

💬Community

4
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001)2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal8: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]2018-02-23
Bugzilla
CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]2018-02-23
CVE-2017-6930 — Improper Access Control in Drupal | cvebase