Incorrect Authorization The advisory has been revoked - it doesn't affect any version of package drupal7  (opens in a new tab)


Threat Intelligence

EPSS
0.54% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1404-DRUPAL7-5488577
  • published28 Apr 2023
  • disclosed26 Apr 2023

Introduced: 26 Apr 2023

CVE-2023-31250  (opens in a new tab)
CWE-863  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:14.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream drupal7 package and not the drupal7 package as distributed by Ubuntu.

The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. Some sites may require configuration changes following this security release. Review the release notes for your Drupal version if you have issues accessing private files after updating.