S3scanner is a utility tool for auditing Amazon S3 bucket configurations, with a niche vulnerability footprint concentrated in its core scanner product. The observed weakness class centers on path-traversal conditions that can arise in pathname handling during bucket enumeration and access validation. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S3scanner Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32061MEDIUM S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element. | Nov 29, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S3scanner Project.
Media articles that mention a CVE ID that affects a product developed by S3scanner Project — matched by CVE ID, not by vendor name.