CVE-2017-6921: File REST resource does not properly validate
Published Jun 21, 2017
·Updated
File REST resource does not properly validate
Affected Software
5 affected componentsFixes available
composer/drupal/core>=8.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.3.4
composer/drupal/drupal>=8.0, <8.1.0, >=8.1.0, <8.2.0, >=8.2.0, <8.3.0, >=8.3.0, <8.3.4
composer/drupal/drupal>=8.0<8.3.4
8.3.4
composer/drupal/core>=8.0<8.3.4
8.3.4
Drupal Drupal>=8.0.0<8.3.4
Event History
Jun 21, 2017
Advisory Published
06:13 PM
Jan 15, 2019
CVE Published
via NVD·09:29 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6921?
CVE-2017-6921 is rated as a moderate severity vulnerability in Drupal 8.
2
How do I fix CVE-2017-6921?
To fix CVE-2017-6921, you should update to Drupal version 8.3.4 or later.
3
Which versions of Drupal are affected by CVE-2017-6921?
CVE-2017-6921 affects Drupal 8 versions prior to 8.3.4.
4
What components need to be enabled for CVE-2017-6921 to be a concern?
For CVE-2017-6921 to be relevant, the RESTful Web Services module and the file REST resource must be enabled.
5
Can CVE-2017-6921 allow unauthorized file manipulation?
Yes, CVE-2017-6921 could lead to unauthorized manipulation of files if exploited.