diff --git a/misconfiguration/s3-torrent.yaml b/misconfiguration/s3-torrent.yaml index 7c77662ad8..16078901ac 100644 --- a/misconfiguration/s3-torrent.yaml +++ b/misconfiguration/s3-torrent.yaml @@ -1,10 +1,14 @@ id: s3-torrent info: - name: S3 torrent Downloads Allowed + name: Amazon S3 Torrent Download - Detect author: ambassify severity: info - description: Detects if endpoint allows magic S3 torrent argument to download files + description: Amazon S3 Torrent download was detected, which can allow a malicious user to download files. + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N + cvss-score: 0.0 + cwe-id: CWE-200 tags: misconfig,aws,s3,bucket requests: @@ -19,3 +23,5 @@ requests: - 'RequestTorrentOfBucketError' - 's3-tracker' condition: or + +# Enhanced by md on 2023/02/06