PT-2026-53930 · Seaweedfs · Seaweedfs
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SeaweedFS versions prior to 4.34
Description
A path traversal issue exists in the S3 gateway
DeleteMultipleObjectsHandler. Authenticated S3 principals with write access to one bucket can delete arbitrary objects in buckets belonging to other tenants. This occurs when object keys containing ../ sequences are supplied in the DeleteObjects XML request body. The flaw stems from a confused deputy condition where the validateRequestPath middleware only inspects URL-captured path variables and ignores request-body keys, allowing the filer path to resolve deletions outside the authorized bucket.Recommendations
Update SeaweedFS to version 4.34 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seaweedfs