Vulnerabilidades em rustfs

33 resultados
Análise Vexday

O rustfs apresenta 25 vulnerabilidades catalogadas, com 5 classificadas como críticas, mas nenhuma sob ataque ativo conhecido até o momento. A preocupação maior é a velocidade de divulgação recente: 13 vulnerabilidades nos últimos 90 dias, indicando descoberta ativa ou correção de problemas latentes. A fraqueza dominante (CWE-862, autorização inadequada) sugere falhas estruturais de controle de acesso que demandam revisão arquitetural.

CVE-2026-55189HIGHRustFS: FTP frontend skips IAM authorization on object readsEPSS 0.2%CVE-2026-55188HIGHRustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsEPSS 0.2%CVE-2026-55838MEDIUMRustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metricsEPSS 0.2%CVE-2026-45040MEDIUMRustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]EPSS 0.2%CVE-2026-46685MEDIUMRustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on consoleEPSS 0.1%CVE-2026-73284HIGHRustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service AccountsEPSS CVE-2026-73287MEDIUMRustFS: FTPS MKD bypasses IAM CreateBucket authorizationEPSS CVE-2026-73290MEDIUMRustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallbackEPSS CVE-2026-73285HIGHRustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untaggedEPSS CVE-2026-73289HIGHRustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisionsEPSS CVE-2026-73265MEDIUMRustFS: Version-specific object reads authorize the non-version actionEPSS CVE-2026-73288MEDIUMRustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deletedEPSS CVE-2026-73286HIGHRustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditionsEPSS