BIT-drupal-2023-31250

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/drupal/BIT-drupal-2023-31250.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-drupal-2023-31250
Aliases
Published
2024-03-06T10:51:40.782Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. Some sites may require configuration changes following this security release. Review the release notes for your Drupal version if you have issues accessing private files after updating.

Database specific
{
    "cpes": [
        "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / drupal

Package

Name
drupal
Purl
pkg:bitnami/drupal

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.96.0
Introduced
9.4.0
Fixed
9.4.14
Introduced
9.5.0
Fixed
9.5.8
Introduced
10.0.0
Fixed
10.0.8