VDB
Sign up
—

DRUPAL-CONTRIB-2023-053

Details

The Xsendfile module enables fast transfer for private files in Drupal.

In order to control private file downloads, the module overrides `ImageStyleDownloadController`, for which a vulnerability was disclosed in [SA-CORE-2023-005](https://www.drupal.org/sa-core-2023-005). The Xsendfile module was still based on an insecure version of `ImageStyleDownloadController`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/xsendfile
Introduced in: 0Fixed in: 1.2.0

Upgrade drupal/xsendfile to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References