CVE-2017-6379: Drupal

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

Affected products

  • Drupal Drupal: version 8.2.0 only; version 8.2.1 only; version 8.2.2 only; version 8.2.3 only; version 8.2.4 only; version 8.2.5 only; …

Published 2017-03-16. Last modified 2026-06-17.