漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover
Vulnerability Description
RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx extension-based PDF preview path can render HTML content uploaded as .pdf, allowing stored cross-site scripting in the management console and exposure of administrator AccessKeyId, SecretAccessKey, and SessionToken values. This is caused by a regression of CVE-2026-27822. This vulnerability is fixed in 0.1.10.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
RustFS Console 跨站脚本漏洞
Vulnerability Description
RustFS Console是RustFS组织开源的一款服务器控制台管理软件。 RustFS Console 0.1.7版本至0.1.10之前版本存在跨站脚本漏洞,该漏洞源于components/object/preview-modal.tsx和components/object/pdf-viewer.tsx中基于扩展名的PDF预览路径可渲染上传为.pdf的HTML内容,可能导致存储型跨站脚本攻击,并泄露管理员AccessKeyId、SecretAccessKey和SessionToken值。
CVSS Information
N/A
Vulnerability Type
N/A