Any storage file can be downloaded from p.sh if full server path is known
Package
Affected versions
>= 2.0.0, <= 2.5.24
<= 1.13.6
Patched versions
2.5.24.1
1.13.6.1
Description
Reviewed
Sep 14, 2021
Published to the GitHub Advisory Database
Sep 14, 2021
Last updated
Jan 9, 2023
The default configuration for platform.sh (.platform.app.yaml) allows access to uploaded files if you know or can guess their location, regardless of whether roles grant content read access to the content containing those files. If you're using Legacy Bridge, the default configuration also allows access to certain legacy files that should not be readable, including the legacy var directory and extension directories.
References