Combined image style
Anyone without logging in could force the server to generate many new images without the right security token. They could not view any hidden files and they could not alter any existing images.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Combined image style to 1.0.7.
For developers: what the fix changed
The fix adds validation in `ImageStyleDownloadController::deliverCombined()` to throw a `NotFoundHttpException` if the requested image style names do not fully resolve. It also updates `CombinedImageStyle::getPathToken()` to return a random string instead of an empty string when there are no image styles, preventing empty tokens from bypassing validation.
Also in this release Added functional tests for combined image style delivery.
src/Controller/ImageStyleDownloadController.php+23 −1 fixsrc/Entity/CombinedImageStyle.php+9 −0 fix