Total vulnerabilities in the database
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
Software | From | Fixed in |
---|---|---|
drupal / drupal | 8.2.5 | 8.2.5.x |
drupal / drupal | 8.2.0 | 8.2.0.x |
drupal / drupal | 8.2.0-beta3 | 8.2.0-beta3.x |
drupal / drupal | 8.2.3 | 8.2.3.x |
drupal / drupal | 8.2.0-rc1 | 8.2.0-rc1.x |
drupal / drupal | 8.2.0-beta2 | 8.2.0-beta2.x |
drupal / drupal | 8.2.0-rc2 | 8.2.0-rc2.x |
drupal / drupal | 8.2.4 | 8.2.4.x |
drupal / drupal | 8.2.6 | 8.2.6.x |
drupal / drupal | 8.2.1 | 8.2.1.x |
drupal / drupal | 8.2.2 | 8.2.2.x |
drupal / drupal | 8.2.0-beta1 | 8.2.0-beta1.x |