plugin

Amazon S3 And Cloudfront Vulnerabilities

2 known security issues reported for the Amazon S3 And Cloudfront WordPress plugin. Most recent disclosed Apr 17, 2023.

1 medium

Running Amazon S3 And Cloudfront on your site? Check whether your installed version is affected.

Scan your site free

guzzlehttp/psr7 < 1.9.1 & 2.4.5 - Interpretation Conflict

medium

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild wi...

CVSS:
5.3
Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Apr 17, 2023

CVE-2023-29197 on NVD →

WP Offload Media Lite for Amazon S3, DigitalOcean Spaces, and Google Cloud Storage [amazon-s3-and-cloudfront] < 3.2.2

unknown

[en] guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wi...

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Apr 17, 2023

CVE-2023-29197 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database