PT-2026-56467 · Seaweedfs · Seaweedfs
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SeaweedFS versions 4.08 through 4.33
Description
Requests signed with the SigV4 service
s3tables are routed to the S3Tables management API. In this process, authorization collapses account-less S3 identities into a shared admin account and fails open. This allows an authenticated low-privileged S3 user to enumerate Amazon Resource Names (ARNs) and table bucket names owned by the administrator.Recommendations
Update SeaweedFS to version 4.34.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seaweedfs