S3 File System - Moderately critical - Access bypass - SA-CONTRIB-2023-014

Project: S3 File SystemVersion: 8.x-3.18.x-3.08.x-3.0-rc28.x-3.0-rc18.x-3.0-beta78.x-3.0-beta68.x-3.0-beta58.x-3.0-beta48.x-3.0-beta38.x-3.0-beta28.x-3.0-beta18.x-3.0-alpha17Date: 2023-May-03Security risk: Moderately critical 13∕25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassDescription: S3 File System (s3fs) provides an additional file system to your Drupal site, which stores files in Amazon's Simple Storage Service (S3) or any other S3-compatible storage service.
This module may fail to validate that a file being requested to be moved to storage was uploaded during the same web request, possibly allowing an attacker to move files that should normally be inaccessible to them.
This vulnerability is mitigated by the fact that another vulnerability must already exist outside of s3fs.Solution: Install the latest version:

  • If you use the S3 File System module for Drupal 8.x, upgrade to s3fs 8.x-3.2

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2023-014