This module enables you to utilize S3-compatible storage as a Drupal filesystem.
The module doesn't sufficiently prevent file access across multiple filesystem schemes stored in the same bucket.
This vulnerability is mitigated by the fact that an attacker must obtain a method to access arbitrary file paths, the site must have public or private takeover enabled, and the file metadata cache must be ignored.
See S3 File System - Moderately critical - Access bypass - SA-CONTRIB-2022-057 for more information.
VCS Label
7.x-2.14
Core compatibility
Release type
Packaged Git sha1
f1a880c1ad2d40292162b041298bbee621c11f65
Release files
16aae52af0ba29d196bd2afe098678cd
Release file SHA-1 hash
8f3809a2e651395760216171798f090675eb0744
Release file SHA-256 hash
3109bd8f074925399497c51b9dc41bffcbe0fe6d1f9fdf55a33a6730f7073b23
64faeacbde7f253db0166b8f4050b8cb
Release file SHA-1 hash
b7286048ee16de1eba7c2f13d3248e05d58a2d08
Release file SHA-256 hash
498d20bd10fa7eb8094399a5c27f66bc771129d01fea500e03b2f2ba8df244ac