Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to authenticated clients.
Upgrade to S3Proxy 2.6.0 which includes apache/jclouds@b0819e0ef5e08c792a4d1724b938714ce9503aa3 and 86b6ee4749aa163a78e7898efc063617ed171980.
None
Privately reported by XBOW Team @xbow-security.
{ "nvd_published_at": "2025-02-03T21:15:16Z", "cwe_ids": [ "CWE-22" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-02-03T17:56:03Z" }