Total vulnerabilities in the database
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
Software | From | Fixed in |
---|---|---|
drupal / drupal | 8.2.5 | 8.2.5.x |
drupal / drupal | 8.2.0 | 8.2.0.x |
drupal / drupal | 8.2.0-beta3 | 8.2.0-beta3.x |
drupal / drupal | 8.2.3 | 8.2.3.x |
drupal / drupal | 8.2.0-rc1 | 8.2.0-rc1.x |
drupal / drupal | 8.2.0-beta2 | 8.2.0-beta2.x |
drupal / drupal | 8.2.0-rc2 | 8.2.0-rc2.x |
drupal / drupal | 8.2.4 | 8.2.4.x |
drupal / drupal | 8.2.6 | 8.2.6.x |
drupal / drupal | 8.2.1 | 8.2.1.x |
drupal / drupal | 8.2.2 | 8.2.2.x |
drupal / drupal | 8.2.0-beta1 | 8.2.0-beta1.x |