Vulnerabilities in rustfs
33 resultsVexday analysis
O rustfs apresenta 25 vulnerabilidades catalogadas, com 5 classificadas como críticas, mas nenhuma sob ataque ativo conhecido até o momento. A preocupação maior é a velocidade de divulgação recente: 13 vulnerabilidades nos últimos 90 dias, indicando descoberta ativa ou correção de problemas latentes. A fraqueza dominante (CWE-862, autorização inadequada) sugere falhas estruturais de controle de acesso que demandam revisão arquitetural.
CVE-2025-68926CRITICALRustFS has a gRPC Hardcoded Token Authentication BypassEPSS 31.9%CVE-2025-68705HIGHRustFS Path Traversal VulnerabilityEPSS 7.4%CVE-2026-47136MEDIUMRustFS: Unauthenticated RustFS console license endpoint exposes license metadataEPSS 0.5%CVE-2026-45044HIGHRustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlersEPSS 0.5%CVE-2026-22782LOWRustFS RPC signature verification logs shared secretEPSS 0.5%CVE-2026-73284HIGHRustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service AccountsEPSS 0.5%CVE-2026-62378CRITICALRustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account TakeoverEPSS 0.5%CVE-2026-40937HIGHRustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooksEPSS 0.5%CVE-2026-45039CRITICALRustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonationEPSS 0.5%CVE-2026-73285HIGHRustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untaggedEPSS 0.5%CVE-2026-22042MEDIUMRustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege EscalationEPSS 0.4%CVE-2026-22043MEDIUMRustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account MintingEPSS 0.4%CVE-2026-73286HIGHRustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditionsEPSS 0.4%CVE-2026-73290MEDIUMRustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallbackEPSS 0.4%CVE-2026-73265MEDIUMRustFS: Version-specific object reads authorize the non-version actionEPSS 0.4%CVE-2026-49991HIGHRustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injectionEPSS 0.4%CVE-2026-73289HIGHRustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisionsEPSS 0.4%CVE-2026-27607HIGHRustFS's Missing Post Policy Validation leads to Arbitrary Object WriteEPSS 0.4%CVE-2026-45041HIGHRustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgeryEPSS 0.4%CVE-2026-73288MEDIUMRustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deletedEPSS 0.4%