DRUPAL-CONTRIB-2023-053

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/xsendfile/DRUPAL-CONTRIB-2023-053.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2023-053
Published
2023-11-29T15:27:05Z
Modified
2026-09-10T03:46:18Z
Summary
[none]
Details

The Xsendfile module enables fast transfer for private files in Drupal.

In order to control private file downloads, the module overrides ImageStyleDownloadController, for which a vulnerability was disclosed in SA-CORE-2023-005. The Xsendfile module was still based on an insecure version of ImageStyleDownloadController.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/xsendfile

Package

Name
drupal/xsendfile
Purl
pkg:composer/drupal/xsendfile?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.0
Database specific
Show details
{
    "constraint": "<1.2.0"
}

Database specific

affected_versions
"<1.2.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/xsendfile/DRUPAL-CONTRIB-2023-053.json"