Impact
RustFS, a distributed object storage system, had a flaw in its Open Policy Agent (OPA) authorization plugin in the 1.0.0-alpha.64 to 1.0.0-rc.1 releases. The plugin incorrectly set the flag that determines whether existing object tags must be considered during policy evaluation, causing tag‑based conditions (s3:ExistingObjectTag/*) to be omitted. Consequently, users who are authenticated to the system could perform operations on objects that were protected by tag‑based policies as though the objects were untagged, effectively bypassing the intended authorization controls. The weakness is an incomplete authorization check (CWE‑863).
Affected Systems
RustFS version 1.0.0-alpha.64 through 1.0.0-rc.1
Risk and Exploitability
The vulnerability scores a CVSS base of 7.5, indicating a high impact when exploited. The EPSS score is unavailable, but there is no indication of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors are remote, involving authenticated users sending requests that pass through the OPA authorization plugin. Successful exploitation would allow those users to access or manipulate objects that should be restricted by tag‑based policy rules.
OpenCVE Enrichment