The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.drupal.org/SA-CORE-2016-004 | vendor advisory |
http://www.securityfocus.com/bid/93101 | third party advisory vdb entry |
http://www.securitytracker.com/id/1036886 | third party advisory vdb entry |