Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59092

Опубликовано: 02 июл. 2026
Источник: nvd
CVSS3: 7.7
CVSS3: 9.8
EPSS Низкий

Описание

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline endpoint to obtain the process command line containing metadata engine connection strings with database credentials, granting full read/write access to filesystem metadata, while other pprof handlers leak internal state and profiling handlers enable denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:juicedata:juicefs:*:*:*:*:*:*:*:*
Версия до 1.3.1 (включая)

EPSS

Процентиль: 30%
0.00377
Низкий

7.7 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-489

Связанные уязвимости

CVSS3: 7.7
github
около 2 месяцев назад

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline endpoint to obtain the process command line containing metadata engine connection strings with database credentials, granting full read/write access to filesystem metadata, while other pprof handlers leak internal state and profiling handlers enable denial of service.

EPSS

Процентиль: 30%
0.00377
Низкий

7.7 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-489