- Issue created by @dokumori
(included for reference. Please do not report access denied as an error.)
There are possible multiple vulnerabilities involving mod_mime_magic and certain web server settings.
After some discussions, the security team came to the conclusion that publishing the PSA is sufficient to address the issues. The link to the draft PSA is found in https://security.drupal.org/node/169010
10.2 ✨
It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.