RustFS是RustFS组织开源的一款网络存储文件系统。 RustFS 1.0.0-beta.12之前版本存在授权问题漏洞,该漏洞源于对ForAllValues和ForAnyValue集合限定符与否定字符串运算符的评估使用了彼此的语义,可能导致Allow条件授予被排除主体访问权限或Deny防护失败。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73284 | 8.8 HIGH | RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts |
| CVE-2026-73286 | 8.1 HIGH | RustF: Request headers can populate server-derived IAM condition keys, letting a caller sa |
| CVE-2026-73285 | 7.5 HIGH | RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authoriza |
| CVE-2026-73265 | 6.5 MEDIUM | RustFS: Version-specific object reads authorize the non-version action |
| CVE-2026-73288 | 6.1 MEDIUM | RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot b |
| CVE-2026-73287 | 5.4 MEDIUM | RustFS: FTPS MKD bypasses IAM CreateBucket authorization |
| CVE-2026-73290 | 5.3 MEDIUM | RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket |
No comments yet