First published: Tue Apr 21 2015(Updated: )
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Web Services (AWS) | <=7.x-1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3373 is considered a moderate severity vulnerability, as it allows remote attackers to guess access tokens.
To fix CVE-2015-3373, upgrade the Amazon AWS module for Drupal to version 7.x-1.3 or later.
CVE-2015-3373 affects the Amazon AWS module for Drupal versions up to and including 7.x-1.2.
The impact of CVE-2015-3373 is that it allows attackers to create backups by guessing the access token.
Users of the Amazon AWS module for Drupal versions prior to 7.x-1.3 are affected by CVE-2015-3373.