CVE-2025-24961

MEDIUM

org.gaul S3Proxy <2.6.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to users. This issue has been addressed in version 2.6.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v4 6.0
EPSS 0.0051
EPSS Percentile 39.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
gaul/s3proxy < 2.6.0
org.gaul/s3proxy 0 - 2.6.0Maven
Published Feb 03, 2025
Tracked Since Feb 18, 2026