Some administrative paths did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

Part of security release SA-CORE-2017-001

This vulnerability affects the following application versions:

  • Drupal 8.0.0
  • Drupal 8.0.1
  • Drupal 8.0.2
  • Drupal 8.0.3
  • Drupal 8.0.4
  • Drupal 8.0.5
  • Drupal 8.0.6
  • Drupal 8.1.0
  • Drupal 8.1.1
  • Drupal 8.1.2
  • Drupal 8.1.3
  • Drupal 8.1.4
  • Drupal 8.1.5
  • Drupal 8.1.6
  • Drupal 8.1.7
  • Drupal 8.1.8
  • Drupal 8.1.9
  • Drupal 8.1.10
  • Drupal 8.2.0
  • Drupal 8.2.1
  • Drupal 8.2.2
  • Drupal 8.2.3
  • Drupal 8.2.4
  • Drupal 8.2.5
  • Drupal 8.2.6

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *