rustfs是RustFS组织开源的一个高性能对象存储系统。 RustFS 1.0.0-beta.4版本存在路径遍历漏洞,该漏洞源于Snowball自动提取功能中存在路径遍历问题,涉及tar条目键规范化中缺乏../清理、IAM通配符匹配使用原始路径以及文件系统路径清理跨存储桶边界解析../,可能导致已认证用户将任意对象写入其他用户的存储桶。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55188 | 8.2 HIGH | RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials |
| CVE-2026-55189 | 7.7 HIGH | RustFS: FTP frontend skips IAM authorization on object reads |
| CVE-2026-55838 | 4.3 MEDIUM | RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated u |
No comments yet