Rustfs

Rustfs

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.02.2026 03:16:07
  • Zuletzt bearbeitet 25.02.2026 15:36:59

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management ...

  • EPSS 0.09%
  • Veröffentlicht 25.02.2026 03:16:04
  • Zuletzt bearbeitet 25.02.2026 15:37:08

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, star...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 16:06:17
  • Zuletzt bearbeitet 23.02.2026 18:18:34

RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access key, secret key, session token) to application logs at INFO level. This results in credentials being re...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 16:06:08
  • Zuletzt bearbeitet 23.02.2026 20:26:41

RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be bypassed: get_condition_values trusts client-supplied X-Forwarded-For/X-Real-Ip without verifying a trusted proxy, so any reachable...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 16.01.2026 16:14:15
  • Zuletzt bearbeitet 09.02.2026 20:47:26

RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.01.2026 15:15:45
  • Zuletzt bearbeitet 15.01.2026 21:13:08

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted servi...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 08.01.2026 14:58:10
  • Zuletzt bearbeitet 15.01.2026 21:11:34

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions t...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 07.01.2026 20:34:25
  • Zuletzt bearbeitet 16.01.2026 19:28:22

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed gRPC GetMetrics request causes get_metrics to unwrap() failed deserialization of metric_type/opts, panicking the handler thread and...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 07.01.2026 20:31:44
  • Zuletzt bearbeitet 16.01.2026 19:29:47

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha...

Exploit
  • EPSS 7.21%
  • Veröffentlicht 30.12.2025 16:59:53
  • Zuletzt bearbeitet 16.01.2026 19:31:07

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on...