In Drupal 8 prior to 8.3.7; When using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. This issue only affects sites that have the RESTful Web Services (rest) module enabled, the comment entity REST resource enabled, and where an attacker can access a user account on the site with permissions to post comments, or where anonymous users can post comments.
History

Mon, 16 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
Title REST API can bypass comment approval - Access Bypass - Moderately Critical REST API can bypass comment approval - Access Bypass - Moderately Critical

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2019-01-15T20:00:00Z

Updated: 2024-09-16T16:57:56.911Z

Reserved: 2017-03-16T00:00:00

Link: CVE-2017-6924

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-01-15T20:29:00.237

Modified: 2023-11-07T02:49:59.893

Link: CVE-2017-6924

cve-icon Redhat

No data.