Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BUG]: Unclaimed s3 bucket at GH forked repo: https://github.com/GoodRx/moto/blob/d3df810065c9c453d40fcc971f9be6b7b2846061/moto/awslambda/models.py#L107 #13

Open
bhartisaurav opened this issue Feb 13, 2025 · 0 comments

Comments

@bhartisaurav
Copy link

Hello team,

I know it is not a correct place to report it but i couldn't find any.

I found an unclaimed s3 bucket at GH forked repo : moto . This repo was updated 9 years ago, i think is no longer in use but parent repo has updated/or removed the s3 bucket link i.e:

[s3 bucket] : s3://lambda-functions.aws.amazon.com

Image

Image

If you are no longer using it, then you can choose to archive it or update the bucket link. This issue can easily lead to XSS to arbitrary code injection at users end if user try to access even by mistake.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant