PT-2026-60353 · Drupal+2 · Drupal Core+1
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal core versions 0.0.0 through 10.6.13
Drupal core versions 11.3.0 through 11.3.14
Drupal core versions 11.4.0 through 11.4.4
Drupal core versions 0.0.0 through 11.0.x
Drupal core versions 0.0.0 through 11.1.x
Drupal core versions 0.0.0 through 11.2.x
Description
A missing authorization issue in the Image module allows forceful browsing, leading to information disclosure. The module fails to sufficiently check access to image style derivatives when files are served via a file stream other than
private://. This issue occurs when Drupal is configured to use a contributed file scheme to serve private derived images.Recommendations
Update versions 0.0.0 through 10.6.13 to a newer version.
Update versions 11.3.0 through 11.3.14 to a newer version.
Update versions 11.4.0 through 11.4.4 to a newer version.
Update versions 0.0.0 through 11.0.x to a newer version.
Update versions 0.0.0 through 11.1.x to a newer version.
Update versions 0.0.0 through 11.2.x to a newer version.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal Core
Drupal