Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55874

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.

A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate X-Amz-Copy-Source headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user, even if scoped to a single bucket, to read objects from other buckets through server-side copy operations. The vulnerability results in unauthorized information disclosure across storage buckets.

Отчет

Important: This flaw in SeaweedFS allows an authenticated attacker to bypass intended access controls within the S3 API gateway. By crafting a malicious X-Amz-Copy-Source header with "dot-dot" path segments, an attacker with limited bucket access can read objects from other unauthorized buckets. This could lead to unauthorized information disclosure in Red Hat Cryostat deployments utilizing SeaweedFS for storage.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2498092SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal

EPSS

Процентиль: 47%
0.00606
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
3 месяца назад

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.

CVSS3: 7.7
debian
3 месяца назад

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API g ...

CVSS3: 7.7
github
25 дней назад

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

EPSS

Процентиль: 47%
0.00606
Низкий

7.7 High

CVSS3