CVE-2017-6931
Dashboard / Vulnerabilities / CVE-2017-6931
Summary:
Details: In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but does not harden against other such bypasses. This vulnerability can be mitigated by disabling the Settings Tray module.
References: https://www.drupal.org/sa-core-2018-001
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- abfe77673a5a6194ef13600e05f1ca2c5dd59db8
Affected versions
8.4.4
8.4.3
8.4.1
8.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
