Project: 
Date: 
2020-September-16
Vulnerability: 
Information disclosure
CVE IDs: 
CVE-2020-13670
Description: 
A vulnerability exists in the File module which allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file.
Solution: 
Install the latest version:
- If you are using Drupal 8.8.x, upgrade to Drupal 8.8.10.
 - If you are using Drupal 8.9.x, upgrade to Drupal 8.9.6.
 - If you are using Drupal 9.0.x, upgrade to Drupal 9.0.6.
 
Versions of Drupal 8 prior to 8.8.x are end-of-life and do not receive security coverage. Sites on 8.7.x or earlier should update to 8.8.10.
Reported By: 
- David Rothstein of the Drupal Security Team
 - Ivan
 - elarlang
 - Mori Sugimoto of the Drupal Security Team
 - kyk
 - njbooher
 
Fixed By: 
- Michael Hess of the Drupal Security Team
 - Peter Wolanin of the Drupal Security Team
 - Stefan Ruijsenaars
 - David Rothstein of the Drupal Security Team
 - Jess of the Drupal Security Team
 - Ben Dougherty of the Drupal Security Team
 - Frédéric G. Marand
 - Samuel Mortenson of the Drupal Security Team
 - Joseph Zhao, provisional member of the Drupal Security Team
 - Lee Rowlands of the Drupal Security Team