RustFS versions prior to 1.0.0-alpha.94 contain an authentication bypass vulnerability in the notification target admin API endpoints. The affected code in rustfs/src/admin/handlers/event.rs performs only authentication validation without proper admin authorization checks, a deficiency unique among admin handlers in the codebase. This allows non-admin authenticated users to overwrite shared notification targets, redirecting bucket events to attacker-controlled endpoints. The vulnerability carries a CVSS score of 8.3 (HIGH) with a network-based attack vector requiring only low complexity and low privilege user credentials. The impact spans confidentiality (event interception across users), integrity (unauthorized modification of notification targets), and availability concerns. An authenticated non-admin user can exploit this with no user interaction required to compromise event delivery and audit trails. There is no evidence of active exploitation in the wild, with an EPSS score of 0.0005 indicating low prevalence among disclosed vulnerabilities. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog, and no public exploit code has been identified. A patch is available in RustFS version 1.0.0-alpha.94, and affected organizations should prioritize upgrading to remediate the authorization control gap.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha1:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha10:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha11:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha12:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha13:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.