Description
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
Remediation
References
Related Vulnerabilities
Atlassian Jira Other Vulnerability (CVE-2019-14997)
Python Resource Management Errors Vulnerability (CVE-2011-1521)
OpenVPN AS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2061)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4407)