Description
The File Force Download module adds a download parameter to file URLs so that a file is sent to the browser as an attachment, or displayed inline, instead of being served with its own default disposition.
The module implements Drupal's file download hook, where returning any header at all is itself a grant of access to the file, but it consults the other implementations of that hook only when the file lives in the private file system. For a file in the temporary file system, or in any other stream wrapper that a contributed module provides, the module returns download headers unconditionally, and because Drupal merges the headers from every implementation, that grant overrides the denial the responsible module would otherwise have returned. The flaw therefore weakens Drupal's own file delivery path rather than only the module's own, and it neutralises the access decisions of every other module on the site.
This vulnerability is mitigated by the requirement that the requester know the exact path of the file, and by the module being installed on relatively few sites. It is not mitigated by configuration, because no setting turns the behaviour off and the module reaches this state as soon as it is enabled.
Solution
Install the latest version.
If you use the File Force Download module for Drupal 7, upgrade to File Force Download 7.x-1.3:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES