VulnerabilityModified
CVE-2015-3373
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
MEDIUM 5.0EPSS 2.07%
Does this matter?
Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.
Description
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.07% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- amazon aws project/amazon aws
- Source
- cve@mitre.org
References
- http://cgit.drupalcode.org/aws_amazon/commit/?id=9377a26
- http://www.openwall.com/lists/oss-security/2015/01/29/6
- http://www.securityfocus.com/bid/74277
- https://www.drupal.org/node/2415457Patch
- https://www.drupal.org/node/2415873Patch, Vendor Advisory
- http://cgit.drupalcode.org/aws_amazon/commit/?id=9377a26
- http://www.openwall.com/lists/oss-security/2015/01/29/6
- http://www.securityfocus.com/bid/74277
- https://www.drupal.org/node/2415457Patch
- https://www.drupal.org/node/2415873Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.