PT-2026-44470 · Rustfs · Rustfs
Mr-In4Inci3Le
·
Published
2026-05-28
·
Updated
2026-05-28
·
CVE-2026-45042
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustFS versions prior to 1.0.0-beta.2
Description
Improper authorization in the
UploadPartCopy operation allows copying objects across buckets without enforcing destination bucket restrictions on allowed copy sources. The system validates GetObject permission on the source bucket and PutObject on the destination bucket independently, but fails to enforce policy constraints regarding whether the destination bucket permits the specified copy source, enabling unauthorized cross-bucket data movement.Recommendations
Update to version 1.0.0-beta.2.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustfs