CVE-2015-3373
Summary
| CVE | CVE-2015-3373 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-21 16:59:31 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Amazon Aws Project | Amazon Aws | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Drupal Amazon AWS Module CVE-2015-3373 Access Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Access bypass vulnerability (9377a267) · Commits · project / aws_amazon · GitLab | af854a3a-2127-422b-91ae-364da2661108 | cgit.drupalcode.org | |
| aws_amazon 7.x-1.3 | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch |
| SA-CONTRIB-2015-030 - Amazon AWS - Access bypass | Drupal.org | af854a3a-2127-422b-91ae-364da2661108 | www.drupal.org | Patch, Vendor Advisory |
| oss-security - Re: CVEs for Drupal contributed modules - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.