Craft CMS Amazon S3 Plugin Information Disclosure Vulnerability
Vulnerability
A low-severity information disclosure vulnerability exists in the Amazon S3 for Craft CMS plugin, specifically in versions 2.0.2 through 2.2.4. The issue allows unauthenticated users to access a list of S3 buckets that the plugin can interact with. This vulnerability arises because the `BucketsController->actionLoadBucketData()` endpoint permits unauthenticated users, provided they have a valid CSRF token, to view the buckets accessible to the plugin.
Impact
Exploitation of this vulnerability allows for unauthorized access to information about S3 buckets that the plugin can access, potentially leading to further information disclosure or misuse of that access.
Remediation
Users are advised to update the Amazon S3 for Craft CMS plugin to version 2.2.5 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
