Writable RubyCi Amazon s3 bucket

Disclosed: 2017-02-27 02:05:26 By dataalchemist To ruby
High
Vulnerability Details
Hello, I have discovered that the bucket: http://rubyci.s3.amazonaws.com/ is able to be written to by authenticated aws users. This is due to the current permissions configurations I have added a file here: http://rubyci.s3.amazonaws.com/test.html for proof of concept. This can be potentially dangerous to your users and website, as any of the web content in this bucket may be replaced with malicious files. More info about these permissions can be found here: http://docs.aws.amazon.com/AmazonS3/latest/dev/s3-access-control.html
Actions
View on HackerOne
Report Stats
  • Report ID: 207053
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report