drupal/core is vulnerable to Information Disclosure
40
Medium Risk
The Image module does not sufficiently check access to image style derivatives when those files are served via a file stream other than private://, which can disclose image derivatives that should remain restricted. This is mitigated by the requirement that Drupal be configured to use a contributed (non-core) file scheme to serve private derived images.
You are affected if you are using a version that falls within the vulnerable range and your site uses a contributed (non-core) file scheme to serve private image style derivatives.
drupal/core is vulnerable to Information Disclosure in versions 0.0.0 - 10.6.12, 11.0.0 - 11.3.13 and 11.4.0 - 11.4.3.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant