rustfs是RustFS组织开源的一个高性能对象存储系统。 RustFS 1.0.0-alpha.1至1.0.0-beta.8版本存在授权问题漏洞,该漏洞源于FTP读取和处理程序直接调度到存储后端而未调用IAM授权函数,可能导致任何能进行FTP身份验证的用户无视IAM策略读取任意存储桶中的任意对象。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-49991 | 8.6 HIGH | RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection |
| CVE-2026-55188 | 8.2 HIGH | RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials |
| CVE-2026-55838 | 4.3 MEDIUM | RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated u |
No comments yet