CVE-2017-6926
Dashboard / Vulnerabilities / CVE-2017-6926
Summary:
Details: In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by the fact that the comment system must be enabled and the attacker must have permission to post comments.
References: https://www.drupal.org/sa-core-2018-001
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- abfe77673a5a6194ef13600e05f1ca2c5dd59db8
Affected versions
8.4.4
8.4.3
8.4.1
8.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
