Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed_at": "2024-04-23T22:34:34Z",
"github_reviewed": true,
"nvd_published_at": "2017-04-20T02:59:00Z",
"severity": "HIGH"
}