¡¾·ì϶¹«¸æ¡¿RustFS PostObject Õ½ÊõÑé֤ȱʧµ¼ÖÂÊÚÈ¨ÈÆ¹ý·ì϶(CVE-2026-27607)
°ä²¼¹¦·ò 2026-02-26Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | RustFS PostObject Õ½ÊõÑé֤ȱʧµ¼ÖÂÊÚÈ¨ÈÆ¹ý·ì϶ | ||
CVE ID | CVE-2026-27607 | ||
·ì϶ÀàÐÍ | ÊÚÈ¨ÈÆ¹ý | ·¢ÏÖ¹¦·ò | 2026-2-26 |
·ì϶ÆÀ·Ö | 9.1 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
RustFSÊÇÒ»¿î»ùÓÚRust˵»°¿ª·¢µÄÉ¢²¼Ê½¶ÔÏó´æ´¢ÏµÍ³£¬Ñ¡È¡¸ß»úÄÜ¡¢Äڴ氲ȫµÄÉè¼ÆÀíÏ룬֧³ÖS3¼æÈݽӿÚÓ뼯Ⱥ»¯²¿Ê𣬺ÏÓÃÓÚÔÆ´æ´¢¡¢Êý¾Ýºþ¼°´ó¹æÄ£·Ç½á¹¹»¯Êý¾Ý³¡¾°¡£¸ÃÏîĿǿµ÷¸ß¿ÉÓᢿÉÀ©´óÓë¸ß²¢·¢´¦ÖÃÄÜÁ¦£¬³£ÓÃÓÚ¹¹½¨×ÔÓжÔÏó´æ´¢»ù´¡ÉèÊ©¡£
2026Äê2ÔÂ26ÈÕ£¬GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½RustFS PostObject Õ½ÊõÑé֤ȱʧµ¼ÖÂÊÚÈ¨ÈÆ¹ý·ì϶£¬¸Ã·ì϶ԴÓÚ·þÎñ¶Ëδ¶ÔÊðÃûÕ½Êõ£¨Policy£©ÖеĹؼüÏÞ¶ÈǰÌá½øÐÐÓÐЧ½âÎöÓëÑéÖ¤£¬Ô̺¬content-length-range¡¢starts-withÒÔ¼°Content-TypeµÈÔ¼Êø£¬µ¼Ö¹¥»÷Õß¿ÉÈÆ¹ý¼È¶¨ÉÏ´«Õ½Êõ¡£ÀûÓøÃȱµã£¬¹¥»÷Õß¿ÉÉÏ´«³¬³öÏÞ¶È´óÓ×µÄÎļþ¡¢½«¶ÔÏóдÈëËÁÒâKeyõè¾¶£¬»òαÔìÎļþÀàÐÍ£¬´Ó¶øÒý·¢´æ´¢×ÊÔ´ºÄ¾¡¡¢Ô½È¨Êý¾Ý¸²¸Ç¼°Ç±ÔڵĿçÕ¾¾ç±¾·çÏÕ¡£
¶þ¡¢Ó°ÏìÁìÓò
1.0.0-alpha.56 <= RustFS <= 1.0.0-alpha.82
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/rustfs/rustfs/tags/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ