rustfs kayıtları
rustfs üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-862 Missing Authorization2
- CWE-269 Improper Privilege Management1
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-20 Improper Input Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2025-68926Kavram kanıtı | RustFS has a gRPC Hardcoded Token Authentication Bypassrustfs · rustfs · CWE-287 | Kritik9,8 | — | %31,9 | 30 Ara 2025 |
37İzleyin | CVE-2025-68705Kavram kanıtı | RustFS Path Traversal Vulnerabilityrustfs · rustfs · CWE-22 | Yüksek8,8 | — | %7,4 | 7 Oca 2026 |
36İzleyin | CVE-2026-27607Kavram kanıtı | RustFS's Missing Post Policy Validation leads to Arbitrary Object Writerustfs · rustfs · CWE-20 | Kritik9,1 | — | %0,4 | 24 Şub 2026 |
33İzleyin | CVE-2026-40937İstismar yok | RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooksrustfs · rustfs · CWE-862 | Yüksek8,3 | — | %0,5 | 22 Nis 2026 |
30İzleyin | CVE-2026-21862İstismar yok | RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headersrustfs · rustfs · CWE-290 | Yüksek7,7 | — | %0,2 | 3 Şub 2026 |
27İzleyin | CVE-2026-24762İstismar yok | RustFS Logs Sensitive Credentials in Plaintextrustfs · rustfs · CWE-532 | Orta6,9 | — | %0,3 | 3 Şub 2026 |
22İzleyin | CVE-2026-22042İstismar yok | RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalationrustfs · rustfs · CWE-285 | Orta5,7 | — | %0,4 | 8 Oca 2026 |
22İzleyin | CVE-2026-22043İstismar yok | RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Mintingrustfs · rustfs · CWE-269 | Orta5,7 | — | %0,4 | 8 Oca 2026 |
22İzleyin | CVE-2025-69255İstismar yok | RustFS gRPC GetMetrics deserialization panic enables remote DoSrustfs · rustfs · CWE-755 | Orta5,5 | — | %0,3 | 7 Oca 2026 |
21İzleyin | CVE-2026-27822İstismar yok | Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeoverrustfs · rustfs · CWE-79 | Orta5,4 | — | %0,4 | 24 Şub 2026 |
21İzleyin | CVE-2026-39360İstismar yok | RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltrationrustfs · rustfs · CWE-862 | Orta5,3 | — | %0,3 | 7 Nis 2026 |
11İzleyin | CVE-2026-22782İstismar yok | RustFS RPC signature verification logs shared secretrustfs · rustfs · CWE-532 | Düşük2,9 | — | %0,5 | 16 Oca 2026 |
- CVE-2025-6892649Planlayın
RustFS has a gRPC Hardcoded Token Authentication Bypass
KritikCVSS 9,8Kavram kanıtıEPSS %32rustfs · rustfs30 Ara 2025
- CVE-2025-6870537İzleyin
RustFS Path Traversal Vulnerability
YüksekCVSS 8,8Kavram kanıtıEPSS %7rustfs · rustfs7 Oca 2026
- CVE-2026-2760736İzleyin
RustFS's Missing Post Policy Validation leads to Arbitrary Object Write
KritikCVSS 9,1Kavram kanıtıEPSS %0rustfs · rustfs24 Şub 2026
- CVE-2026-4093733İzleyin
RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks
YüksekCVSS 8,3İstismar yokEPSS %0rustfs · rustfs22 Nis 2026
- CVE-2026-2186230İzleyin
RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
YüksekCVSS 7,7İstismar yokEPSS %0rustfs · rustfs3 Şub 2026
- CVE-2026-2476227İzleyin
RustFS Logs Sensitive Credentials in Plaintext
OrtaCVSS 6,9İstismar yokEPSS %0rustfs · rustfs3 Şub 2026
- CVE-2026-2204222İzleyin
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
OrtaCVSS 5,7İstismar yokEPSS %0rustfs · rustfs8 Oca 2026
- CVE-2026-2204322İzleyin
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
OrtaCVSS 5,7İstismar yokEPSS %0rustfs · rustfs8 Oca 2026
- CVE-2025-6925522İzleyin
RustFS gRPC GetMetrics deserialization panic enables remote DoS
OrtaCVSS 5,5İstismar yokEPSS %0rustfs · rustfs7 Oca 2026
- CVE-2026-2782221İzleyin
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
OrtaCVSS 5,4İstismar yokEPSS %0rustfs · rustfs24 Şub 2026
- CVE-2026-3936021İzleyin
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
OrtaCVSS 5,3İstismar yokEPSS %0rustfs · rustfs7 Nis 2026
- CVE-2026-2278211İzleyin
RustFS RPC signature verification logs shared secret
DüşükCVSS 2,9İstismar yokEPSS %1rustfs · rustfs16 Oca 2026