Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-6377

20
FAUCET Score

CVE-2017-6377 describes an access bypass vulnerability in Drupal 8.2.x before 8.2.7, where private files attached via the editor do not have their access permissions properly checked. This flaw has a CVSSv3 score of 7.5 (HIGH), indicating a network-exploitable vulnerability with low attack complexity that can lead to high integrity impact, allowing unauthorized access to private files. While no active exploitation, Metasploit, or ExploitDB modules are publicly available, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
8.2.0CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:8.2.0:*:*:*:*:*:*:*
8.2.0CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:8.2.0:beta1:*:*:*:*:*:*
8.2.0CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:8.2.0:beta2:*:*:*:*:*:*
8.2.0CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:8.2.0:beta3:*:*:*:*:*:*
8.2.0CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:8.2.0:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.89%
Probability of exploitation in next 30 days
EPSS Percentile
77.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0189 is in the 61st percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: drupal/coreFixed in: 8.2.7
composerpatch availablevia ghsa
Product: drupal/drupalFixed in: 8.2.7

Vendor Advisories (1)

composerGHSA-w7qx-vwr9-2j3rhigh

Drupal editor module incorrectly checks access to inline private files

May 13, 2022

References

drupal.org / SA-2017-001
Vendor Advisory
securityfocus.com / bid/96919
Third Party AdvisoryVDB Entry
securitytracker.com / id/1038058