HTTP: Drupal Core system.temporary Information Disclosure

An information disclosure vulnerability has been reported in Drupal Core. Successful exploitation could result in the disclosure of sensitive information.

Extended Description

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Affected Products

Drupal drupal

Short Name
HTTP:DRUPAL-INFO-DISCLOSURE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-7572 Core Disclosure Drupal Information system.temporary
Release Date
10/06/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
Vendors

Drupal

CVSS Score

4.0

Found a potential security threat?