CVE-2026-73290
- EPSS 0.24%
- Veröffentlicht 12.08.2026 14:46:20
- Zuletzt bearbeitet 12.08.2026 16:17:22
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns befo...
CVE-2026-73289
- EPSS 0.23%
- Veröffentlicht 12.08.2026 14:43:58
- Zuletzt bearbeitet 12.08.2026 15:18:32
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNo...
CVE-2026-73288
- EPSS 0.25%
- Veröffentlicht 12.08.2026 14:42:50
- Zuletzt bearbeitet 12.08.2026 23:17:24
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner ...
CVE-2026-73287
- EPSS 0.21%
- Veröffentlicht 12.08.2026 14:41:15
- Zuletzt bearbeitet 13.08.2026 17:17:35
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBu...
CVE-2026-73286
- EPSS 0.24%
- Veröffentlicht 12.08.2026 14:40:04
- Zuletzt bearbeitet 12.08.2026 16:17:22
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatur...
CVE-2026-73285
- EPSS 0.35%
- Veröffentlicht 12.08.2026 14:37:42
- Zuletzt bearbeitet 12.08.2026 15:18:31
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrect...
CVE-2026-73284
- EPSS 0.28%
- Veröffentlicht 12.08.2026 14:34:27
- Zuletzt bearbeitet 12.08.2026 23:17:23
RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_ser...
CVE-2026-73265
- EPSS 0.3%
- Veröffentlicht 12.08.2026 14:33:04
- Zuletzt bearbeitet 13.08.2026 17:17:35
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without histori...
CVE-2026-55188
- EPSS 0.18%
- Veröffentlicht 26.06.2026 20:03:52
- Zuletzt bearbeitet 27.06.2026 04:17:51
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication target...
CVE-2026-49991
- EPSS 0.27%
- Veröffentlicht 26.06.2026 20:01:29
- Zuletzt bearbeitet 29.06.2026 14:16:55
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary ob...