craftcms/aws-s3 is vulnerable to Information Disclosure
32
Low Risk
Affected versions of this package are vulnerable to information disclosure due to insufficient access control on the bucket data loading endpoint. Under certain conditions, unauthenticated or unauthorized requests to the controller that loads S3 bucket metadata could expose internal configuration or sensitive information. This is mitigated by enforcing administrator-only access and appropriate request validation on the endpoint, preventing unauthorized access to bucket data.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/aws-s3 is vulnerable to Information Disclosure in versions 1.0.0 - 2.2.4.
Upgrade the craftcms/aws-s3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant