drupal/core is vulnerable to Information Disclosure
60
Medium Risk
Affected versions of this package are vulnerable to Information Disclosure: the Drupal core system module may incorrectly serve private or temporary files with the HTTP header Cache-Control: public, allowing them to be cached by intermediaries such as Varnish or CDNs. This can expose sensitive files to unauthorized users.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Information Disclosure in versions 8.0.0 - 10.4.8, 10.5.0 - 10.5.5, 11.0.0 - 11.1.8 and 11.2.0 - 11.2.7.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant