{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2017-6930","title":"Title"},{"category":"description","text":"In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2017-6930","url":"https://www.suse.com/security/cve/CVE-2017-6930"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1084292 for CVE-2017-6930","url":"https://bugzilla.suse.com/1084292"}],"title":"SUSE CVE CVE-2017-6930","tracking":{"current_release_date":"2025-02-18T07:51:28Z","generator":{"date":"2023-02-15T04:48:36Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2017-6930","initial_release_date":"2023-02-15T04:48:36Z","revision_history":[{"date":"2023-02-15T04:48:36Z","number":"2","summary":"Current version"},{"date":"2025-01-01T09:05:18Z","number":"3","summary":"Current version"},{"date":"2025-02-18T07:51:28Z","number":"4","summary":"Current version"}],"status":"interim","version":"4"}}}