Записи rustfs
12 опубликованных записей вендора rustfs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 83,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-862 Missing Authorization2
- CWE-269 Improper Privilege Management1
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2025-68926Proof of concept | RustFS has a gRPC Hardcoded Token Authentication Bypassrustfs · rustfs · CWE-287 | Критическая9,8 | — | 31,9 % | 30 дек. 2025 г. |
37Наблюдать | CVE-2025-68705Proof of concept | RustFS Path Traversal Vulnerabilityrustfs · rustfs · CWE-22 | Высокая8,8 | — | 7,4 % | 7 янв. 2026 г. |
36Наблюдать | CVE-2026-27607Proof of concept | RustFS's Missing Post Policy Validation leads to Arbitrary Object Writerustfs · rustfs · CWE-20 | Критическая9,1 | — | 0,4 % | 24 февр. 2026 г. |
33Наблюдать | CVE-2026-40937Эксплойта нет | RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooksrustfs · rustfs · CWE-862 | Высокая8,3 | — | 0,5 % | 22 апр. 2026 г. |
30Наблюдать | CVE-2026-21862Эксплойта нет | RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headersrustfs · rustfs · CWE-290 | Высокая7,7 | — | 0,2 % | 3 февр. 2026 г. |
27Наблюдать | CVE-2026-24762Эксплойта нет | RustFS Logs Sensitive Credentials in Plaintextrustfs · rustfs · CWE-532 | Средняя6,9 | — | 0,3 % | 3 февр. 2026 г. |
22Наблюдать | CVE-2026-22042Эксплойта нет | RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalationrustfs · rustfs · CWE-285 | Средняя5,7 | — | 0,4 % | 8 янв. 2026 г. |
22Наблюдать | CVE-2026-22043Эксплойта нет | RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Mintingrustfs · rustfs · CWE-269 | Средняя5,7 | — | 0,4 % | 8 янв. 2026 г. |
22Наблюдать | CVE-2025-69255Эксплойта нет | RustFS gRPC GetMetrics deserialization panic enables remote DoSrustfs · rustfs · CWE-755 | Средняя5,5 | — | 0,3 % | 7 янв. 2026 г. |
21Наблюдать | CVE-2026-27822Эксплойта нет | Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeoverrustfs · rustfs · CWE-79 | Средняя5,4 | — | 0,4 % | 24 февр. 2026 г. |
21Наблюдать | CVE-2026-39360Эксплойта нет | RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltrationrustfs · rustfs · CWE-862 | Средняя5,3 | — | 0,3 % | 7 апр. 2026 г. |
11Наблюдать | CVE-2026-22782Эксплойта нет | RustFS RPC signature verification logs shared secretrustfs · rustfs · CWE-532 | Низкая2,9 | — | 0,5 % | 16 янв. 2026 г. |
- CVE-2025-6892649В плане
RustFS has a gRPC Hardcoded Token Authentication Bypass
КритическаяCVSS 9,8Proof of conceptEPSS 32 %rustfs · rustfs30 дек. 2025 г.
- CVE-2025-6870537Наблюдать
RustFS Path Traversal Vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 7 %rustfs · rustfs7 янв. 2026 г.
- CVE-2026-2760736Наблюдать
RustFS's Missing Post Policy Validation leads to Arbitrary Object Write
КритическаяCVSS 9,1Proof of conceptEPSS 0 %rustfs · rustfs24 февр. 2026 г.
- CVE-2026-4093733Наблюдать
RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %rustfs · rustfs22 апр. 2026 г.
- CVE-2026-2186230Наблюдать
RustFS sourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %rustfs · rustfs3 февр. 2026 г.
- CVE-2026-2476227Наблюдать
RustFS Logs Sensitive Credentials in Plaintext
СредняяCVSS 6,9Эксплойта нетEPSS 0 %rustfs · rustfs3 февр. 2026 г.
- CVE-2026-2204222Наблюдать
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
СредняяCVSS 5,7Эксплойта нетEPSS 0 %rustfs · rustfs8 янв. 2026 г.
- CVE-2026-2204322Наблюдать
RustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
СредняяCVSS 5,7Эксплойта нетEPSS 0 %rustfs · rustfs8 янв. 2026 г.
- CVE-2025-6925522Наблюдать
RustFS gRPC GetMetrics deserialization panic enables remote DoS
СредняяCVSS 5,5Эксплойта нетEPSS 0 %rustfs · rustfs7 янв. 2026 г.
- CVE-2026-2782221Наблюдать
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
СредняяCVSS 5,4Эксплойта нетEPSS 0 %rustfs · rustfs24 февр. 2026 г.
- CVE-2026-3936021Наблюдать
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
СредняяCVSS 5,3Эксплойта нетEPSS 0 %rustfs · rustfs7 апр. 2026 г.
- CVE-2026-2278211Наблюдать
RustFS RPC signature verification logs shared secret
НизкаяCVSS 2,9Эксплойта нетEPSS 1 %rustfs · rustfs16 янв. 2026 г.