Description
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2044)
Oracle Database Server CVE-2021-2175 Vulnerability (CVE-2021-2175)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0737)
PrestaShop Improper Privilege Management Vulnerability (CVE-2023-43663)
Python Improper Input Validation Vulnerability (CVE-2018-20852)