RustFS是RustFS组织开源的一款网络存储文件系统。 RustFS 1.0.0-beta.12之前版本存在授权问题漏洞,该漏洞源于get_condition_values函数将攻击者控制的请求头合并到服务器派生的条件键中,可能允许已认证的调用者满足基于身份的策略条件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: injected "userid" header satisfied IAM policy condition key aws:userid, retrieved PROOF_cdadfa484aaa26c9
| CVE-2026-73284 | 8.8 HIGH | RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts |
| CVE-2026-73289 | 8.1 HIGH | RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM a |
| CVE-2026-73285 | 7.5 HIGH | RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authoriza |
| CVE-2026-73265 | 6.5 MEDIUM | RustFS: Version-specific object reads authorize the non-version action |
| CVE-2026-73288 | 6.1 MEDIUM | RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot b |
| CVE-2026-73287 | 5.4 MEDIUM | RustFS: FTPS MKD bypasses IAM CreateBucket authorization |
| CVE-2026-73290 | 5.3 MEDIUM | RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket |
No comments yet