When added a private file via a configured text editor (like CKEditor), the editor would not correctly check access for the file being attached, resulted in an access bypass.
Part of security patch SA-CORE-2017-001
This vulnerability affects the following application versions:
- Drupal 8.2.2
- Drupal 8.2.3
- Drupal 8.2.4
- Drupal 8.2.5
- Drupal 8.2.6