Skip to content

S3 Bucket Takeover vulnerability  #287

@nvk0x

Description

@nvk0x

Description

I found an unclaimed s3 bucket was using in file, I claimed the bucket and uploaded poc.

Steps to Reproduce:

  1. Go to this link to check code
  2. S3 bucket name: s3.amazonaws.com/navpi-image is using in index.md file
Screenshot 2024-07-07 at 9 41 33 PM
  1. Click here for POC: https://s3.amazonaws.com/navpi-image/index.html
Screenshot 2024-07-07 at 9 50 16 PM

Fix:

Please remove this S3 bucket from the code or tell me i will delete this bucket from my aws account and claim it.

Impact:

  • Attacker can get navcoin employees private IPs Whenever navcoin developers run this project
  • Attacker can host malicious content on this bucket

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions