An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.
References
Link | Resource |
---|---|
https://gist.github.com/iTrooz/629bd30cfa09cc527a0859e8cca83a4b | Third Party Advisory |
https://gist.github.com/iTrooz/629bd30cfa09cc527a0859e8cca83a4b | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-09 21:15
Updated : 2024-11-21 09:24
NVD link : CVE-2024-37865
Mitre link : CVE-2024-37865
CVE.ORG link : CVE-2024-37865
JSON object : View
Products Affected
s3browser
- s3_browser
CWE
CWE-295
Improper Certificate Validation