Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
2017-04-20T02:59:00.143
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.0 | Yes |
Application | drupal | drupal | 8.0.1 | Yes |
Application | drupal | drupal | 8.0.2 | Yes |
Application | drupal | drupal | 8.0.3 | Yes |
Application | drupal | drupal | 8.0.4 | Yes |
Application | drupal | drupal | 8.0.5 | Yes |
Application | drupal | drupal | 8.0.6 | Yes |
Application | drupal | drupal | 8.1.0 | Yes |
Application | drupal | drupal | 8.1.0 | Yes |
Application | drupal | drupal | 8.1.0 | Yes |
Application | drupal | drupal | 8.1.0 | Yes |
Application | drupal | drupal | 8.1.1 | Yes |
Application | drupal | drupal | 8.1.2 | Yes |
Application | drupal | drupal | 8.1.3 | Yes |
Application | drupal | drupal | 8.1.4 | Yes |
Application | drupal | drupal | 8.1.5 | Yes |
Application | drupal | drupal | 8.1.6 | Yes |
Application | drupal | drupal | 8.1.7 | Yes |
Application | drupal | drupal | 8.1.8 | Yes |
Application | drupal | drupal | 8.1.9 | Yes |
Application | drupal | drupal | 8.1.10 | Yes |
Application | drupal | drupal | 8.2.0 | Yes |
Application | drupal | drupal | 8.2.0 | Yes |
Application | drupal | drupal | 8.2.0 | Yes |
Application | drupal | drupal | 8.2.0 | Yes |
Application | drupal | drupal | 8.2.0 | Yes |
Application | drupal | drupal | 8.2.0 | Yes |
Application | drupal | drupal | 8.2.1 | Yes |
Application | drupal | drupal | 8.2.2 | Yes |
Application | drupal | drupal | 8.2.3 | Yes |
Application | drupal | drupal | 8.2.4 | Yes |
Application | drupal | drupal | 8.2.5 | Yes |
Application | drupal | drupal | 8.2.6 | Yes |
Application | drupal | drupal | 8.2.7 | Yes |
Application | drupal | drupal | 8.3.0 | Yes |
Application | drupal | drupal | 8.3.0 | Yes |
Application | drupal | drupal | 8.3.0 | Yes |
Application | drupal | drupal | 8.3.0 | Yes |
Application | drupal | drupal | 8.3.0 | Yes |