Intel

AIKIDO-2026-10273

craftcms/aws-s3 is vulnerable to Information Disclosure

Information DisclosureGHSA-hwj7-4vgc-j3v9 Published Mar 2, 2026

32

Low Risk

This Affects:

PHPcraftcms/aws-s3
1.0.0 - 2.2.4
Fixed in 2.2.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to information disclosure due to insufficient access control on the bucket data loading endpoint. Under certain conditions, unauthenticated or unauthorized requests to the controller that loads S3 bucket metadata could expose internal configuration or sensitive information. This is mitigated by enforcing administrator-only access and appropriate request validation on the endpoint, preventing unauthorized access to bucket data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/aws-s3 is vulnerable to Information Disclosure in versions 1.0.0 - 2.2.4.

How to fix this

Upgrade the craftcms/aws-s3 library to the patch version.