CVE-2015-3373: Infoleak
Published Apr 21, 2015
·Updated
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
Affected Software
1 affected component
Amazon Aws Project Amazon Aws Drupal<=7.x-1.2
Remediation
Patch Available
Patch Available
Event History
Apr 21, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3373?
CVE-2015-3373 is considered a moderate severity vulnerability, as it allows remote attackers to guess access tokens.
2
How do I fix CVE-2015-3373?
To fix CVE-2015-3373, upgrade the Amazon AWS module for Drupal to version 7.x-1.3 or later.
3
What versions of the Amazon AWS module are affected by CVE-2015-3373?
CVE-2015-3373 affects the Amazon AWS module for Drupal versions up to and including 7.x-1.2.
4
What is the impact of CVE-2015-3373?
The impact of CVE-2015-3373 is that it allows attackers to create backups by guessing the access token.
5
Who is affected by CVE-2015-3373?
Users of the Amazon AWS module for Drupal versions prior to 7.x-1.3 are affected by CVE-2015-3373.