Project:
Date:
2020-September-16
Vulnerability:
Information disclosure
CVE IDs:
CVE-2020-13670
Description:
A vulnerability exists in the File module which allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file.
Solution:
Install the latest version:
- If you are using Drupal 8.8.x, upgrade to Drupal 8.8.10.
- If you are using Drupal 8.9.x, upgrade to Drupal 8.9.6.
- If you are using Drupal 9.0.x, upgrade to Drupal 9.0.6.
Versions of Drupal 8 prior to 8.8.x are end-of-life and do not receive security coverage. Sites on 8.7.x or earlier should update to 8.8.10.
Reported By:
- David Rothstein of the Drupal Security Team
- Ivan
- elarlang
- Mori Sugimoto of the Drupal Security Team
- kyk
Fixed By:
- Michael Hess of the Drupal Security Team
- Peter Wolanin of the Drupal Security Team
- Stefan Ruijsenaars
- David Rothstein of the Drupal Security Team
- Jess of the Drupal Security Team
- Ben Dougherty of the Drupal Security Team
- Frédéric G. Marand
- Samuel Mortenson of the Drupal Security Team
- Joseph Zhao, provisional member of the Drupal Security Team