Описание
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.
A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate X-Amz-Copy-Source headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user, even if scoped to a single bucket, to read objects from other buckets through server-side copy operations. The vulnerability results in unauthorized information disclosure across storage buckets.
Отчет
Important: This flaw in SeaweedFS allows an authenticated attacker to bypass intended access controls within the S3 API gateway. By crafting a malicious X-Amz-Copy-Source header with "dot-dot" path segments, an attacker with limited bucket access can read objects from other unauthorized buckets. This could lead to unauthorized information disclosure in Red Hat Cryostat deployments utilizing SeaweedFS for storage.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.7 High
CVSS3
Связанные уязвимости
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.
7.7 High
CVSS3