An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://gist.github.com/iTrooz/629bd30cfa09cc527a0859e8cca83a4b | third party advisory |