Stave scanner finds 47 security issues in default S3 configs of Mastodon, Discourse and Chatwoot
Open-source tool Stave analyzed the AWS S3 configurations that Rails apps get by following their documentation. Mastodon and Discourse default to publicly readable uploads, and none of the three projects configures encryption, access logging or Public Access Block.
- 47 findings across Mastodon, Discourse and Chatwoot
- Mastodon sets public-read ACL unless S3_PERMISSION is set
- Discourse does the same with s3_use_acls=true and secure_uploads=false
- Chatwoot is the only one not public-read by default
Read next
Security