CVE-2017-6919: High severity Drupal Drupal vulnerability
Access bypass
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.3.1 - Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 8.2.8 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.3.1 - Upgrade
Upgrade
composer/drupal/coreto a version that resolves this vulnerability.Fixed in 8.2.8 - Upgrade
Upgrade
Drupal 8to a version that resolves this vulnerability.Fixed in 8.2.8 - Upgrade
Upgrade
Drupal 8to a version that resolves this vulnerability.Fixed in 8.3.1 - Configuration
To prevent critical access bypass, ensure the site does not allow PATCH requests when the RESTful Web Services (rest) module is enabled.
Drupal 8 REST module (rest) PATCH requests allowed = disallow PATCH (disable PATCH support)
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6919?
CVE-2017-6919 is classified as a critical severity vulnerability.
How do I fix CVE-2017-6919?
To fix CVE-2017-6919, update your Drupal installation to versions 8.2.8 or 8.3.1 or later.
Who is affected by CVE-2017-6919?
CVE-2017-6919 affects Drupal 8 installations prior to version 8.2.8 and 8.3 prior to 8.3.1 when the RESTful Web Services module is enabled.
What kind of attack does CVE-2017-6919 allow?
CVE-2017-6919 allows authenticated users to bypass access controls leading to potential unauthorized changes.
What versions of Drupal are vulnerable to CVE-2017-6919?
Drupal versions from 8.0.0 up to 8.3.0 are vulnerable to CVE-2017-6919.