CVE-2017-6925
Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions
9.8
CRITICAL
CVSS 3.1
EPSS 0.62%
Description
In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs, and entities that have different access restrictions on different revisions of the same entity.
How to fix CVE-2017-6925
To remediate CVE-2017-6925, upgrade the affected package to a fixed version below.
- —upgrade to 8.3.7 or later
- —upgrade to 8.3.7 or later
Is CVE-2017-6925 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 8.0, < 8.3.7
- >= 8.0, < 8.3.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |