PT-2023-37004 · Packagist · Drupal/S3Fs
Published
2023-05-03
·
Updated
2023-05-03
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
S3 File System (s3fs) provides an additional file system to your Drupal site, which stores files in Amazon's Simple Storage Service (S3) or any other S3-compatible storage service.
This module may fail to validate that a file being requested to be moved to storage was uploaded during the same web request, possibly allowing an attacker to move files that should normally be inaccessible to them.
This vulnerability is mitigated by the fact that another vulnerability must already exist outside of s3fs.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal/S3Fs