CVE-2026-45043
- EPSS 0.23%
- Veröffentlicht 29.05.2026 12:25:08
- Zuletzt bearbeitet 02.06.2026 02:16:15
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, i...
- EPSS 0.11%
- Veröffentlicht 28.05.2026 18:41:35
- Zuletzt bearbeitet 29.05.2026 15:11:03
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Origin and als...
CVE-2026-45039
- EPSS 0.27%
- Veröffentlicht 28.05.2026 18:39:54
- Zuletzt bearbeitet 29.05.2026 15:11:03
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() i...
CVE-2026-45040
- EPSS 0.15%
- Veröffentlicht 28.05.2026 18:35:48
- Zuletzt bearbeitet 02.06.2026 14:16:54
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensitive credentials including SessionToken (JWT), Secre...
CVE-2026-45041
- EPSS 0.24%
- Veröffentlicht 28.05.2026 18:34:06
- Zuletzt bearbeitet 29.05.2026 15:16:23
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses it in production via parse_license() to "verify" lic...
CVE-2026-45042
- EPSS 0.21%
- Veröffentlicht 28.05.2026 18:32:31
- Zuletzt bearbeitet 29.05.2026 15:11:03
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing destination bucket restrictions on allowed copy sources...
CVE-2026-45044
- EPSS 0.31%
- Veröffentlicht 28.05.2026 18:31:39
- Zuletzt bearbeitet 29.05.2026 15:11:03
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling ha...
CVE-2026-47136
- EPSS 0.31%
- Veröffentlicht 28.05.2026 18:30:08
- Zuletzt bearbeitet 29.05.2026 15:11:03
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentication. The endpoint is registered on the console li...
CVE-2026-40937
- EPSS 0.29%
- Veröffentlicht 22.04.2026 20:15:57
- Zuletzt bearbeitet 24.04.2026 13:12:29
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions` helper that validates authentication only (access...
CVE-2026-39360
- EPSS 0.2%
- Veröffentlicht 07.04.2026 18:58:29
- Zuletzt bearbeitet 10.04.2026 19:03:17
RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket can still ex...