Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
{
    "severity": "HIGH",
    "nvd_published_at": "2017-04-20T02:59:00Z",
    "github_reviewed_at": "2024-04-23T22:34:34Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-284"
    ]
}