5

CVE-2015-3373

The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amazon Aws ProjectAmazon Aws SwPlatformdrupal Version <= 7.x-1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.09% 0.791
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.openwall.com/lists/oss-security/2015/01/29/6
http://cgit.drupalcode.org/aws_amazon/commit/?id=9377a26
http://www.securityfocus.com/bid/74277
https://www.drupal.org/node/2415457
Patch
https://www.drupal.org/node/2415873
Patch
Vendor Advisory