rustfs是RustFS组织开源的一个高性能对象存储系统。 RustFS 1.0.0-alpha.1版本至1.0.0-beta.8版本存在安全漏洞,该漏洞源于bucket replication admin API中的授权绕过问题,可能导致经过身份验证但无有效权限的用户列出存储桶的远程复制目标配置,并泄露复制访问密钥和秘密密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49991 | 8.6 HIGH | RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection |
| CVE-2026-55189 | 7.7 HIGH | RustFS: FTP frontend skips IAM authorization on object reads |
| CVE-2026-55838 | 4.3 MEDIUM | RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated u |
No comments yet