In some situations, the Image module does not correctly check access to image files that are not stored in the standard public files directory when generating derivative images using the image styles system.
Access to a non-public file is checked only if it is stored in the "private" file system. However, some contributed modules provide additional file systems, or schemes, which may lead to this vulnerability.
Some sites may require configuration changes following this security release. Review the Backdrop release notes if you have issues accessing files or image styles after updating.
- Backdrop Core 1.22.x versions prior to 1.22.1
- Backdrop Core 1.21.x versions prior to 1.21.6
Backdrop versions 1.20 and prior do not receive security coverage.