Open S3 Bucket Accessible by any User

Disclosed: 2022-04-13 07:12:58 By ravansurya To omise
Unknown
Vulnerability Details
hi team, here i found Open S3 Bucket Accessible by any User vulnerable URL: https://cdn2.omise.co/ bucket name : `omise-cdn-2` I haven't tried this yet as it may delete the bucket. (it is possible) an Attacker can delete the bucket using this command:- $ aws s3 rb s3://<The_bucket_name> and claim the bucket again to takeover the bucket https://cdn2.omise.co/. (S3 misconfiguration), that allow to any user listing/read/download all folders/files. i think somthing misconfiguration is happaening here, u cant read the bucket using Aws Cli but u can read it via browser. and also u can download the file using both Aws Cli and Browser. ████████ download: ██████ ## Impact Sensitive information Leakage. an Attacker can delete the bucket .and claim the bucket again to takeover the buckaet
Actions
View on HackerOne
Report Stats
  • Report ID: 1474017
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report