Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

53N4Do

#44104of 53,624
6.1Total CVSS
Vulnerabilities · 1
PT-2024-22591
6.1
2024-03-11
Amazon Aws · Aws-Js-S3-Explorer · CVE-2024-28823
**Name of the Vulnerable Software and Affected Versions** Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) version 1.0.0 **Description** The issue allows for XSS via a crafted S3 bucket name to index.html. This can be exploited when a user interacts with a maliciously named S3 bucket, potentially leading to the execution of unauthorized code. **Recommendations** For Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) version 1.0.0, as a temporary workaround, consider validating and sanitizing S3 bucket names to prevent malicious input. At the moment, there is no information about a newer version that contains a fix for this vulnerability.