CVE Browser
RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback
RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions
RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted
RustFS: FTPS MKD bypasses IAM CreateBucket authorization
RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions
RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged
RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts
RustFS: Version-specific object reads authorize the non-version action
RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection
RustFS: FTP frontend skips IAM authorization on object reads
RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics
RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root
RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata endpoint on console
RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation
RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs [Debug Mode]
RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery
RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source
RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated access to profiling handlers
RustFS: Unauthenticated RustFS console license endpoint exposes license metadata
RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
RustFS's Missing Post Policy Validation leads to Arbitrary Object Write
Showing 1 to 25 CVEs · page 1 (more available)