GHSA-7ffh-cjvg-fpr4

Suggest an improvement
Source
https://github.com/advisories/GHSA-7ffh-cjvg-fpr4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7ffh-cjvg-fpr4/GHSA-7ffh-cjvg-fpr4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7ffh-cjvg-fpr4
Aliases
Published
2022-05-13T01:46:49Z
Modified
2024-04-23T23:11:43.109017Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Drupal Settings Tray access bypass
Details

In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but does not harden against other such bypasses. This vulnerability can be mitigated by disabling the Settings Tray module.

Database specific
{
    "nvd_published_at": "2018-03-01T23:29:00Z",
    "cwe_ids": [
        "CWE-434"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-23T22:35:39Z"
}
References

Affected packages

Packagist / drupal/core

Package

Name
drupal/core
Purl
pkg:composer/drupal/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.4.0
Fixed
8.4.5

Affected versions

8.*

8.4.0
8.4.1
8.4.2
8.4.3
8.4.4

Packagist / drupal/drupal

Package

Name
drupal/drupal
Purl
pkg:composer/drupal/drupal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.4.0
Fixed
8.4.5

Affected versions

8.*

8.4.0
8.4.1
8.4.2
8.4.3
8.4.4