S3 File System - Moderately critical - Access bypass - SA-CONTRIB-2022-057

S3 File System - Moderately critical - Access bypass - SA-CONTRIB-2022-057

Project: S3 File System
Date: 2022-September-28
Security risk: Moderately critical 10∕25
Vulnerability: Access bypass

Description

This module enables you to utilize S3-compatible storage as a Drupal filesystem.

The module doesn't sufficiently prevent file access across multiple filesystem schemes stored in the same bucket.

This vulnerability is mitigated by the fact that an attacker must obtain a method to access arbitrary file paths, the site must have public or private takeover enabled, and the file metadata cache must be ignored.

Solution

Install the latest version:

Nick Onom's picture
Nick Onom
Marketing Project Manager
Enthusiastic about all kinds of Open Source applications, AI, bitcoins, but mostly Drupal and Backdrop. For last years has been actively developing AltaGrade's new back-end system.

We value your opinion. Please add your feedback.