First published: Wed Jun 21 2017(Updated: )
Files uploaded by anonymous users into a private file system can be accessed by other anonymous users
Credit: mlhess@drupal.org mlhess@drupal.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/core | >=8.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.3.4 | |
composer/drupal/drupal | >=8.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.3.4 | |
debian/drupal7 | <=7.52-2<=7.32-1 | 7.56-1 7.52-2+deb9u1 7.32-1+deb8u9 |
debian/drupal7 | ||
composer/drupal/drupal | >=7.0<7.56 | 7.56 |
composer/drupal/drupal | >=8.0<8.3.4 | 8.3.4 |
composer/drupal/core | >=8.0<8.3.4 | 8.3.4 |
composer/drupal/core | >=7.0<7.56 | 7.56 |
Drupal | >=7.0<7.56 | |
Drupal | >=8.0.0<8.3.4 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-6922 is classified as moderate since it allows anonymous users to access private files uploaded by other anonymous users.
To fix CVE-2017-6922, update Drupal to version 7.56 or 8.3.4 or later.
CVE-2017-6922 affects Drupal core version 8.x prior to 8.3.4 and 7.x prior to 7.56.
Yes, CVE-2017-6922 can lead to unauthorized data exposure as private files uploaded by anonymous users can be accessed by other anonymous users.
If upgrading is not possible, you should restrict anonymous user access to file uploads to mitigate the risk associated with CVE-2017-6922.