CVE-2017-6379
16.03.2017, 14:59
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
Vendor | Product | Version |
---|---|---|
drupal | drupal | 8.2.0 |
drupal | drupal | 8.2.0:beta1 |
drupal | drupal | 8.2.0:beta2 |
drupal | drupal | 8.2.0:beta3 |
drupal | drupal | 8.2.0:rc1 |
drupal | drupal | 8.2.0:rc2 |
drupal | drupal | 8.2.1 |
drupal | drupal | 8.2.2 |
drupal | drupal | 8.2.3 |
drupal | drupal | 8.2.4 |
drupal | drupal | 8.2.5 |
drupal | drupal | 8.2.6 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration