Impact
RustFS evaluates policy qualifiers incorrectly when negated string operators are used with ForAllValues: and ForAnyValue:. As a result, permissions can be unintentionally granted or denied. This can allow a principal that should be denied access to obtain it, or allow a request that should be blocked to succeed, directly violating confidentiality, integrity, or availability requirements. The flaw is a form of access control bypass (CWE-863).
Affected Systems
RustFS installations running version 1.0.0-beta.11 or earlier are vulnerable; the issue was fixed in 1.0.0-beta.12. All deployments that evaluate IAM or bucket policies with negated string operators using ForAllValues: and ForAnyValue: fall under the affected scope.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, so the precise exploitation likelihood is unclear. However, an attacker who can influence policy content or request values could exploit the mis‑evaluation to bypass intended restrictions, enabling unauthorized data access or violation of security controls. Prompt remediation is recommended for systems exposed to external users or untrusted policy sources.
OpenCVE Enrichment