~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
Candidate: CVE-2017-6919
PublicDate: 2017-04-19
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6919
 https://www.drupal.org/SA-CORE-2017-002
Description:
 Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by
 authenticated users if the RESTful Web Services (rest) module is enabled
 and the site allows PATCH requests.
Ubuntu-Description:
Notes:
 ratliff> Upstream: "Drupal 7.x is not affected."
Bugs:
Priority: high
Discovered-by: Samuel Mortenson
Assigned-to:

Patches_drupal7:
upstream_drupal7: not-affected
precise_drupal7: not-affected
trusty_drupal7: not-affected
vivid/stable-phone-overlay_drupal7: DNE
vivid/ubuntu-core_drupal7: DNE
xenial_drupal7: not-affected
yakkety_drupal7: not-affected
zesty_drupal7: not-affected
devel_drupal7: not-affected