S3browser is a focused utility for managing Amazon S3 cloud storage, where the durable vulnerability signal centers on certificate validation and XML parsing issues that arise in its role as a cloud-credential and data-handling tool. The recurring weakness classes—improper certificate validation and improper restriction of XML external entity references—reflect the security-critical nature of authenticating to cloud services and processing untrusted data streams. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S3browser over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20298MEDIUM S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into | Dec 19, 2018 | 6.5 | 22 | NO | NO |
CVE-2024-37865MEDIUM An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component. | Jul 9, 2024 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S3browser.
Media articles that mention a CVE ID that affects a product developed by S3browser — matched by CVE ID, not by vendor name.