When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: drupal

Published: 2017-03-16T14:00:00

Updated: 2017-07-11T09:57:01

Reserved: 2017-02-28T00:00:00


Link: CVE-2017-6377

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-03-16T14:59:00.237

Modified: 2019-10-03T00:03:26.223


Link: CVE-2017-6377

JSON object: View

cve-icon Redhat Information

No data.

CWE