Skip to content

Insecure path traversal in filesystem and filesystem-nio2 storage backends

Moderate
gaul published GHSA-2ccp-vqmv-4r4x Feb 2, 2025

Package

maven org.gaul.s3proxy (Maven)

Affected versions

< 2.6.0

Patched versions

2.6.0

Description

Impact

Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to authenticated clients.

Patches

Upgrade to S3Proxy 2.6.0 which includes apache/jclouds@b0819e0 and 86b6ee4.

Workarounds

None

References

Privately reported by XBOW Team @xbow-security.

Severity

Moderate

CVE ID

CVE-2025-24961

Weaknesses

No CWEs

Credits