CVE-2015-3373 Information
Feb 14, 2021
cve
Description
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
Reference
http://cgit.drupalcode.org/aws_amazon/commit/?id=9377a26 http://www.openwall.com/lists/oss-security/2015/01/29/6 http://www.securityfocus.com/bid/74277 https://www.drupal.org/node/2415457 https://www.drupal.org/node/2415873
Share on: