Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55874

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.7

Описание

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.

A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate X-Amz-Copy-Source headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user, even if scoped to a single bucket, to read objects from other buckets through server-side copy operations. The vulnerability results in unauthorized information disclosure across storage buckets.

Отчет

Important: This flaw in SeaweedFS allows an authenticated attacker to bypass intended access controls within the S3 API gateway. By crafting a malicious X-Amz-Copy-Source header with "dot-dot" path segments, an attacker with limited bucket access can read objects from other unauthorized buckets. This could lead to unauthorized information disclosure in Red Hat Cryostat deployments utilizing SeaweedFS for storage.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2498092SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
27 дней назад

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.

7.7 High

CVSS3