Date
Severity
Moderately Critical
Vulnerability
Information Disclosure
Affected versions
<7.106

Description

The Image module defines image fields and generates resized derivatives of uploaded images on demand.

When a request carries a valid derivative token, the module treats every file scheme except the core private scheme as public, so it never asks the file download access hook whether the requester may see the source image, and it generates and returns the derivative to any anonymous visitor. A site that serves private images through a contributed stream wrapper therefore discloses those derivatives even though the backing store itself is not reachable over the web, and the unauthorized request also writes a fresh derivative into that store.

This vulnerability is mitigated by the fact that Drupal must be configured to serve private derived images through a contributed file scheme rather than the core private scheme, and by the fact that an attacker must first obtain a valid derivative URL, because the token is a keyed hash that cannot be computed without the site private key and hash salt.

Solution

Install the latest version.


Reported by

Fixed by

Coordinated by