Advisories ยป MGASA-2017-0198

Updated drupal packages fix security vulnerability

Publication date: 29 Jun 2017
Modification date: 29 Jun 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-6922

Description

Greg Knaddison, Mori Sugimoto and iancawthorne discovered that files
uploaded by anonymous users into a private file system can be accessed
by other anonymous users leading to an access bypass vulnerability
(CVE-2017-6922).
                

References

SRPMS

5/core