Juicedata

Juicefs

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 21.08.2026 11:05:13
  • Zuletzt bearbeitet 21.08.2026 22:16:46

The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either filepath.Join(d.root, key) or filepath.Clean(d.root + key) with no c...

  • EPSS 0.38%
  • Veröffentlicht 02.07.2026 19:39:57
  • Zuletzt bearbeitet 17.08.2026 15:40:17

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared htt...