High severity8.1NVD Advisory· Published Mar 1, 2018· Updated Jun 17, 2026
CVE-2017-6930
CVE-2017-6930
Description
In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
drupal/corePackagist | >= 8.4.0, < 8.4.5 | 8.4.5 |
drupal/drupalPackagist | >= 8.4.0, < 8.4.5 | 8.4.5 |
Affected products
4- ghsa-coords2 versions
>= 8.4.0, < 8.4.5+ 1 more
- (no CPE)range: >= 8.4.0, < 8.4.5
- (no CPE)range: >= 8.4.0, < 8.4.5
- Range: 8.4.x versions before 8.4.5
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-3327-jr93-7hq3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-6930ghsaADVISORY
- www.drupal.org/sa-core-2018-001nvdVendor AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2017-6930.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2017-6930.yamlghsaWEB
News mentions
0No linked articles in our index yet.