Loading HuntDB...

GHSA-mmjr-5q74-p3m4

GitHub Security Advisory

Exposure of Resource to Wrong Sphere in Drupal Core

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

Affected Packages

Packagist drupal/core
Affected versions: 8.0.0 (fixed in 8.8.10)
Packagist drupal/core
Affected versions: 8.9.0 (fixed in 8.9.6)
Packagist drupal/core
Affected versions: 9.0.0 (fixed in 9.0.6)
Packagist drupal/drupal
Affected versions: 8.0.0 (fixed in 8.8.10)
Packagist drupal/drupal
Affected versions: 8.9.0 (fixed in 8.9.6)
Packagist drupal/drupal
Affected versions: 9.0.0 (fixed in 9.0.6)

Related CVEs

Key Information

GHSA ID
GHSA-mmjr-5q74-p3m4
Published
February 12, 2022 12:00 AM
Last Modified
February 25, 2022 3:35 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
drupal/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.