CVE-2017-6921 is a medium-severity vulnerability in Drupal 8, specifically versions prior to 8.3.4, where the file REST resource improperly validates fields during file manipulation. This flaw allows an attacker with file upload and modification permissions to compromise data integrity if the RESTful Web Services module is enabled and configured to allow PATCH requests for file resources. The CVSS score of 5.9 indicates a network-based attack with high impact to integrity, though requiring high attack complexity. While SecurityWeek reported exploitation in spam campaigns, there are no public exploit modules like Metasploit or Nuclei, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.3.4CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.