CVE

Id
103197  
CVE No.
CVE-2017-6377  
Status
Candidate  
Description
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.  
Phase
Assigned (20170228)  
Votes
None (candidate not yet proposed)  
Comments