{"id":"CVE-2017-6379","aliases":["GHSA-gxxq-fhc7-3jv9"],"url":"https://o3.security/vulnerability/CVE-2017-6379","summary":"Drupal Cross-Site Request Forgery (CSRF)","details":"Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.","published":"2017-03-16T14:59:00.267Z","modified":"2026-07-08T12:28:06.068479Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.2.7"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.2.7"}],"fix":null,"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96919"},{"type":"WEB","url":"http://www.securitytracker.com/id/1038058"},{"type":"ADVISORY","url":"https://www.drupal.org/SA-2017-001"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-6379"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2017-6379.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2017-6379.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/core"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:28:06.068479Z"}}