Vulnerabilidades en seaweedfs
8 resultadosAnálisis Vexday
SeaweedFS apresenta 5 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco recente e ativo do fornecedor. Nenhuma está atualmente sob ataque explorado em campo (KEV) e não há críticas por CVSS, mas a fraqueza dominante é path traversal (CWE-22), que facilita acesso não autorizado a arquivos. O volume concentrado em janela curta sugere descobertas recentes que merecem avaliação rápida de aplicabilidade ao ambiente.
CVE-2026-58372HIGHSeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body KeysEPSS 0.8%CVE-2026-72920CRITICALSeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlEPSS 0.4%CVE-2026-73080CRITICALSeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedleEPSS 0.4%CVE-2026-54917HIGHSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket accessEPSS 0.4%CVE-2026-55874HIGHSeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object readEPSS 0.3%CVE-2026-72921HIGHSeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsEPSS 0.2%CVE-2026-58371LOWSeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback ParameterEPSS 0.2%CVE-2026-55873MEDIUMSeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table bucketsEPSS 0.2%