Information Disclosure Vulnerability in Drupal Core File Module
CVE-2020-13670
7.5HIGH
What is CVE-2020-13670?
An information disclosure vulnerability exists in the file module of Drupal Core, allowing unauthorized access to file metadata of private files. Attackers can exploit this vulnerability by guessing the file ID, which can lead to exposure of sensitive information. This affects multiple versions of Drupal Core, including 8.8.x before 8.8.10, 8.9.x before 8.9.6, and 9.0.x before 9.0.6. Administrators are encouraged to update their installations to the latest versions to mitigate potential risks.
Affected Version(s)
Core 8.8.x < 8.8.10
Core 8.9.x < 8.9.6
Core 9.0.x < 9.0.6