aws-sdk-go S3 bucket information disclosure |
NAME
__________
aws-sdk-go S3 bucket information disclosure
Platforms Affected:
Amazon AWS SDK for Go 1.30.0
Risk Level:
6.5
Exploitability:
Unproven
Consequences:
Obtain Information
DESCRIPTION
__________
AWS SDK for the Go programming language (aws-sdk-go) could allow a remote authenticated attacker to obtain sensitive information, caused by an arbitrary file read vulnerability. An attacker could exploit this vulnerability to recover the unencrypted S3 bucket content without accessing the encryption key.
CVSS 3.0 Information
__________
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Access Vector:
Network
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
![aws-sdk-go S3 bucket information disclosure | 1 Buy Me A Coffee](https://www.redpacketsecurity.com/wp-content/uploads/2022/10/buymeacoffee.png)
![aws-sdk-go S3 bucket information disclosure | 2 Patreon](https://www.redpacketsecurity.com/wp-content/uploads/2021/01/Digital-Patreon-Wordmark_FieryCoralv2-1024x209.png)
To keep up to date follow us on the below channels.