MGASA-2017-0198
Dashboard / Vulnerabilities / MGASA-2017-0198
Summary: Updated drupal packages fix security vulnerability
Details: Greg Knaddison, Mori Sugimoto and iancawthorne discovered that files uploaded by anonymous users into a private file system can be accessed by other anonymous users leading to an access bypass vulnerability (CVE-2017-6922).
References: https://advisories.mageia.org/MGASA-2017-0198.html, https://bugs.mageia.org/show_bug.cgi?id=21152, https://www.drupal.org/SA-CORE-2017-003, https://www.drupal.org/project/drupal/releases/7.53, https://www.drupal.org/project/drupal/releases/7.54, https://www.drupal.org/project/drupal/releases/7.55, https://www.drupal.org/project/drupal/releases/7.56, https://www.debian.org/security/2017/dsa-3897
Affected packages
Package
Name: drupal
Purl: pkg:rpm/mageia/drupal?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
