Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to authenticated clients.
Upgrade to S3Proxy 2.6.0 which includes apache/jclouds@b0819e0ef5e08c792a4d1724b938714ce9503aa3 and 86b6ee4749aa163a78e7898efc063617ed171980.
None
Privately reported by XBOW Team @xbow-security.
{
"severity": "MODERATE",
"nvd_published_at": "2025-02-03T21:15:16Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-22"
],
"github_reviewed_at": "2025-02-03T17:56:03Z"
}