chiprook
← Security
SecurityOctober 2, 2026, 19:38

Stave scanner finds 47 security issues in default S3 configs of Mastodon, Discourse and Chatwoot

Open-source tool Stave analyzed the AWS S3 configurations that Rails apps get by following their documentation. Mastodon and Discourse default to publicly readable uploads, and none of the three projects configures encryption, access logging or Public Access Block.

Stave scanner finds 47 security issues in default S3 configs of Mastodon, Discourse and Chatwoot
#Mastodon#Discourse#Chatwoot#AWS
Read next
Security

Researchers Used Claude to Hack OpenAI Accounts, Earned $6,500 Bounty

Security

Hacktron used zero-day to reach OpenAI's GitHub, sparking disclosure debate

Security

Citrix NetScaler Exploit Drops Web Shells, Steals Config Data

Security

Scanners Pose as ClaudeBot to Hunt for .env Files