When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038058 | vdb entry |
https://www.drupal.org/SA-2017-001 | vendor advisory |
http://www.securityfocus.com/bid/96919 | third party advisory vdb entry |