- Backdrop Core 1.22.x versions prior to 1.22.1
- Backdrop Core 1.21.x versions prior to 1.21.6
Backdrop versions 1.20 and prior do not receive security coverage.
In some situations, the Image module does not correctly check access to image files that are not stored in the standard public files directory when generating derivative images using the image styles system.
Access to a non-public file is checked only if it is stored in the "private" file system. However, some contributed modules provide additional file systems, or schemes, which may lead to this vulnerability.
Some sites may require configuration changes following this security release. Review the Backdrop release notes if you have issues accessing files or image styles after updating.
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.22.1 release page. See the update instructions, if needed.
- Lee Rowlands of the Drupal Security Team
- Conrad Lara
- mondrake
- Alex Bronstein of the Drupal Security Team
- Dave Reid of the Drupal Security Team
- xjm of the Drupal Security Team
- Guy Elsmore-Paddock
- Dave Long Provisional Member of the Drupal Security Team
- Lauri Eskola Provisional Member of the Drupal Security Team
- David Strauss of the Drupal Security Team
- Benji Fisher Provisional Member of the Drupal Security Team
- Alex Pott of the Drupal Security Team
- Drew Webber of the Drupal Security Team
- Fabian Franz
- Nate Lampton of the Backdrop CMS Security Team