SCA: security update for drupal/core (GHSA-xh3v-6f9j-wxw3)

high Tenable Self-Hosted Container Security Plugin ID 420510

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In some situations, the Image module does not correctly check access to image files not stored in the
standard public files directory when generating derivative images using the image styles system. Access to
a non-public file is checked only if it is stored in the "private" file system. However, some contributed
modules provide additional file systems, or schemes, which may lead to this vulnerability. This
vulnerability is mitigated by the fact that it only applies when the site sets (Drupal 9)
$config['image.settings']['allow_insecure_derivatives'] or (Drupal 7)
$conf['image_allow_insecure_derivatives'] to TRUE. The recommended and default setting is FALSE, and
Drupal core does not provide a way to change that in the admin UI. Some sites may require configuration
changes following this security release. Review the release notes for your Drupal version if you have
issues accessing files or image styles after updating. (CVE-2022-25275)

See Also

https://github.com/advisories/GHSA-xh3v-6f9j-wxw3

Plugin Details

Severity: High

ID: 420510

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2022-25275

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2022

Vulnerability Publication Date: 7/20/2022

Reference Information

CVE: CVE-2022-25275