Description
The Adaptive Image module delivers responsive images by serving image style derivatives that are scaled to the screen resolution it detects for the visitor, through its own delivery routes that are deliberately open to everyone so that the callback itself can decide what may be served.
The callback is a copy of Drupal's own image style delivery function, and it decides whether a file needs an access check by comparing the requested scheme against the single value private. Every other scheme that is not publicly readable, including Drupal's temporary file system and every stream wrapper a contributed module registers, therefore skips the check entirely and falls through to unconditional derivative generation and delivery. The copy additionally carries no derivative token validation at all, so unlike the core function it was derived from, it neither requires the token that proves the site generated the URL nor limits who may cause new derivatives to be written.
This vulnerability is mitigated by the requirement that the requester know the path of the source image, and by the module having to be enabled with at least one image style using its effect. It is not otherwise mitigated, because the temporary file system is always present, no configuration is needed to reach the flaw, and no token is required.
Solution
Install the latest version.
If you use the Adaptive Image module for Drupal 7, upgrade to Adaptive Image 7.x-1.7:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES