CVE-2022-31159 is a partial-path traversal vulnerability in the AWS S3 TransferManager component of the AWS SDK for Java v1 prior to version 1.12.261. This flaw allows a malicious actor to bypass validation logic in the downloadDirectory method by including a UNIX double-dot in an S3 object key, potentially leading to files being written outside the intended destination directory. Rated Medium severity (CVSS 6.5), the vulnerability has a low attack complexity and could result in high confidentiality impact, but no integrity or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.12.260CPE matchmatch criteria | cpe:2.3:a:amazon:aws-sdk-java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.