PT-2026-44474 · Rustfs · Rustfs
Michael Graff
+1
·
Published
2026-05-28
·
Updated
2026-05-28
·
CVE-2026-47136
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustFS versions prior to 1.0.0-beta.2
Description
The console endpoint "GET /rustfs/console/license" returns parsed license metadata, including the license subject and expiration timestamp in JSON format, without requiring authentication. Any client capable of reaching the console listener can query this endpoint without providing credentials.
Recommendations
Update to version 1.0.0-beta.2.
Fix
Information Disclosure
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustfs