QID 983307
QID 983307: Python (pip) Security Update for s3scanner (GHSA-qppg-v75c-r5ff)
S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qppg-v75c-r5ff for updates pertaining to this vulnerability.
Vendor References
- GHSA-qppg-v75c-r5ff -
github.com/advisories/GHSA-qppg-v75c-r5ff
CVEs related to QID 983307
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qppg-v75c-r5ff | s3scanner |
|