Description
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
Remediation
References
Related Vulnerabilities
Apache Tomcat Other Vulnerability (CVE-2001-0829)
Jboss EAP Inadequate Encryption Strength Vulnerability (CVE-2019-14887)
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-23163)
WordPress Plugin Connections Business Directory Unspecified Vulnerability (10.4.7)
Internet Information Services Other Vulnerability (CVE-2000-0226)