One Article Review

Accueil - L'article:
Source NetworkWorld.webp Network World
Identifiant 357910
Date de publication 2017-04-20 14:09:50 (vue: 2017-04-20 14:09:50)
Titre Drupal fixes critical access bypass vulnerability
Texte The Drupal project has released a patch to fix a critical access bypass vulnerability that could put websites at risk of hacking.The vulnerability does not have the highest severity level based on Drupal's rating system, but is serious enough that the platform's developers decided to also release a patch for a version of the content management system that's no longer officially supported.Successful exploitation of the vulnerability can lead to a complete compromise of data confidentiality and website integrity, but only Drupal-based websites with certain configurations are affected.To be vulnerable, a website needs to have the RESTful Web Services enabled and to allow PATCH requests. Furthermore, the attacker needs to be able to register a new account on the website or to gain access to an existing one, regardless of its privileges.To read this article in full or to leave a comment, please click here
Envoyé Oui
Condensat able access account affected allow also are article attacker based but bypass can certain click comment complete compromise confidentiality configurations content could critical data decided developers does drupal enabled enough existing exploitation fix fixes full furthermore gain hacking has have here highest integrity its lead leave level longer management needs new not officially one only patch platform please privileges project put rating read regardless register release released requests restful risk serious services severity successful supported system that version vulnerability vulnerable web website websites
Tags Guideline
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: