Description
The Image module defines image fields and generates resized derivatives of uploaded images on demand.
When a request carries a valid derivative token, the module treats every file scheme except the core private scheme as public, so it never asks the file download access hook whether the requester may see the source image, and it generates and returns the derivative to any anonymous visitor. A site that serves private images through a contributed stream wrapper therefore discloses those derivatives even though the backing store itself is not reachable over the web, and the unauthorized request also writes a fresh derivative into that store.
This vulnerability is mitigated by the fact that Drupal must be configured to serve private derived images through a contributed file scheme rather than the core private scheme, and by the fact that an attacker must first obtain a valid derivative URL, because the token is a keyed hash that cannot be computed without the site private key and hash salt.
Solution
Install the latest version.
Reported by
Fixed by
- Benji Fisher (benjifisher) of the Drupal Security Team
- Kim Pepper (kim.pepper)
- Mohit Aghera (mohit_aghera)
- Tag1 D7ES
Coordinated by
- Benji Fisher (benjifisher) of the Drupal Security Team
- catch (catch) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Tag1 D7ES