Problem/Motivation

This module contains a tweaked copy of ImageStyleDownloadController (used for the image.style_encrypt route).
This version of ImageStyleDownloadController does not seem to include the fix for SA-CORE-2023-005.

Proposed resolution

This fix should probably be applied to the version of ImageStyleDownloadController in file_encrypt.

Comments

prudloff created an issue. See original summary.

shumer’s picture

Assigned: Unassigned » shumer
Status: Active » Needs work

  • shumer committed f201dfb2 on 8.x-1.x
    Issue #3370418 by prudloff, shumer: Module might be vulnerable to SA-...
shumer’s picture

Status: Needs work » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.