Description
S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0224 | S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element. |
Github GHSA |
GHSA-qppg-v75c-r5ff | S3Scanner allows Directory Traversal |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:17:28.777Z
Reserved: 2021-05-05T00:00:00.000Z
Link: CVE-2021-32061
No data.
Status : Modified
Published: 2021-11-29T03:15:06.713
Modified: 2024-11-21T06:06:46.940
Link: CVE-2021-32061
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA