RustFS是RustFS组织开源的一款网络存储文件系统。 RustFS 1.0.0-alpha.64至1.0.0-rc.1之前版本存在授权问题漏洞,该漏洞源于crates/iam/src/sys.rs中通过RUSTFS_POLICY_PLUGIN_URL启用的外部OPA授权错误设置PreparedIamAuth.needs_existing_object_tag,导致maybe_merge_object_tag_conditions省略s3:ExistingObjectTag/*值,允许已认证用户绕过基
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73284 | 8.8 HIGH | RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts |
| CVE-2026-73286 | 8.1 HIGH | RustF: Request headers can populate server-derived IAM condition keys, letting a caller sa |
| CVE-2026-73289 | 8.1 HIGH | RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM a |
| CVE-2026-73265 | 6.5 MEDIUM | RustFS: Version-specific object reads authorize the non-version action |
| CVE-2026-73288 | 6.1 MEDIUM | RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot b |
| CVE-2026-73287 | 5.4 MEDIUM | RustFS: FTPS MKD bypasses IAM CreateBucket authorization |
| CVE-2026-73290 | 5.3 MEDIUM | RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket |
No comments yet