Open API - AWS S3 GET Bucket (List Objects) Version 1
This issue took No information to triage and 6 Days and 6 hours to resolve once triaged.


AWS S3 GET Bucket (List Objects) Version 1 API accesible

Steps To Reproduce:

navigate to:

Observe that you get a listbucketresponse ( The truncated param is set to true, so there are more pages available. we can go te the next page by using the marker parameter and setting it to the NextMarker value.[email protected]

One of the resources that can be discovered is for example:


An attacker can gather info about all items in the bucket, including sensitive data like