漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
Vulnerability Description
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables privilege escalation and bypass of session/inline policy restrictions. Version 1.0.0-alpha.79 fixes the issue.
CVSS Information
N/A
Vulnerability Type
特权管理不恰当
Vulnerability Title
rustfs 安全漏洞
Vulnerability Description
rustfs是RustFS开源的一个高性能对象存储系统。 rustfs 1.0.0-alpha.13版本至1.0.0-alpha.78版本存在安全漏洞,该漏洞源于deny_only短路逻辑缺陷,可能导致权限提升和绕过会话策略限制。
CVSS Information
N/A
Vulnerability Type
N/A