Improper authorization control for web services In drupal/drupal
Description
Drupal access control bypass vulnerability Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 8.2.8, 8.3.1 | ||
packagist | 8.2.8, 8.3.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.