GHSA-3327-jr93-7hq3

Suggest an improvement
Source
https://github.com/advisories/GHSA-3327-jr93-7hq3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3327-jr93-7hq3/GHSA-3327-jr93-7hq3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3327-jr93-7hq3
Aliases
Published
2022-05-13T01:46:48Z
Modified
2024-04-23T22:59:05.700277Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Drupal access bypass vulnerability
Details

In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hooknodeaccess_records().

Database specific
{
    "nvd_published_at": "2018-03-01T23:29:00Z",
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-23T22:34:06Z"
}
References

Affected packages

Packagist / drupal/core

Package

Name
drupal/core
Purl
pkg:composer/drupal/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.4.0
Fixed
8.4.5

Affected versions

8.*

8.4.0
8.4.1
8.4.2
8.4.3
8.4.4

Packagist / drupal/drupal

Package

Name
drupal/drupal
Purl
pkg:composer/drupal/drupal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.4.0
Fixed
8.4.5

Affected versions

8.*

8.4.0
8.4.1
8.4.2
8.4.3
8.4.4