Impact
RustFS is a distributed object storage system, and versions prior to 1.0.0‑beta.12 incorrectly folded attacker‑controlled request headers into server‑derived IAM condition keys such as userid, username, principaltype, groups, versionid, signatureversion, jwt, and ldap. This allowed an authenticated caller to meet identity‑based policy conditions, thereby bypassing access controls and gaining elevated privileges. The weakness is classified as CWE‑863.
Affected Systems
All RustFS releases before 1.0.0‑beta.12 are affected. The vendor is rustfs:rustfs. No exact version ranges are provided beyond the statement that 1.0.0‑beta.12 contains the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity. No EPSS score is available and it is not listed in CISA KEV. Based on the description, it is inferred that attackers need only to send a crafted request with special headers while authenticated, and the remote request is therefore the likely attack vector. By manipulating the headers, the policy engine can accept the forged values, allowing the attacker to trigger privileged operations. Based on the description, it is inferred that the flaw can be exploited remotely and can grant broad permissions, representing a significant risk to environments using earlier RustFS releases.
OpenCVE Enrichment