Amazon · Aws-Js-S3-Explorer · CVE-2019-14652
Name of the Vulnerable Software and Affected Versions:
Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) versions prior to 2019-08-02
Description:
The issue allows for cross-site scripting (XSS) under certain circumstances. XSS is a type of attack where an attacker can inject malicious scripts into a website, potentially allowing them to steal user data or take control of the user's session.
Recommendations:
For versions prior to 2019-08-02, update to a version released after 2019-08-02 to resolve the issue. As a temporary workaround, consider restricting access to the explorer.js file to minimize the risk of exploitation.