CVE-2022-24840 is a critical path traversal vulnerability affecting django-s3file versions prior to 5.5.1, allowing attackers to traverse and potentially access or delete any file within an AWS S3 bucket. Rated 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), this flaw is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, immediate patching to version 5.5.1 or above is strongly recommended as there is no feasible workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5.1CPE matchmatch criteria | cpe:2.3:a:django-s3file_project:django-s3file:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.