Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root
Vulnerability Description
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint accepts attacker-controlled parent, claims, accessKey, and secretKey values without enforcing privilege boundaries or sanitization. This enables privilege escalation to full administrative access using a persistent, attacker-defined credential. This vulnerability is fixed in 1.0.0-beta.2.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
rustfs 访问控制错误漏洞
Vulnerability Description
rustfs是RustFS开源的一个高性能对象存储系统。 rustfs 1.0.0-beta.2之前版本存在访问控制错误漏洞,该漏洞源于PUT /rustfs/admin/v3/import-iam端点验证不当,允许具有ImportIAMAction的用户在任意父身份下创建服务账户,包括root用户,可能导致权限提升至完全管理访问。
CVSS Information
N/A
Vulnerability Type
N/A