mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-25 21:46:50 +00:00
9364ecba67
Signed-off-by: 安正超 <anzhengchao@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
7.9 KiB
7.9 KiB
RustFS Advisory Pattern Map
Snapshot source: gh api repos/rustfs/rustfs/security-advisories --paginate on 2026-05-05. It included 23 advisories: 8 triage, 13 published, and 2 closed.
Refresh this file when new advisories appear or when an advisory changes state materially.
Pattern Index
Admin authorization and route exposure
GHSA-pfcq-4gjr-6gjmpublished: notification target endpoints accepted authenticated users but skipped admin authorization. Lesson: distinguish authn from authz; admin target CRUD must call the operation-specific admin authorization path.GHSA-mm2q-qcmx-gw4wpublished:ListServiceAccountusedUpdateServiceAccountAdminAction, while update lacked target ownership checks. Lesson: exact action constants and ownership checks are both required; information disclosure can chain into secret rotation and takeover.GHSA-vcwh-pff9-64ccpublished:ImportIamcheckedExportIAMActionfor an import/write operation. Lesson: every admin handler must authorize the action it actually performs.GHSA-jqmc-mg33-v45gtriage andGHSA-8784-9m7f-c6p6triage:/profile/cpuand/profile/memorywere whitelisted from auth and allowed expensive diagnostics plus path disclosure. Lesson: profiling/debug endpoints need admin auth, opt-in, rate limits, and non-sensitive responses.GHSA-x5xv-223c-8vm7triage: console license metadata endpoint was public. Lesson: public metadata endpoints should be coarse or authenticated.
IAM import, service accounts, and privilege boundaries
GHSA-566f-q62r-wcr8triage:ImportIamaccepted attacker-controlled service accountparent,claims,accessKey, andsecretKey, enabling persistent backdoor accounts under root. Lesson: imported IAM payloads are untrusted data and must be validated against privilege boundaries.GHSA-xgr5-qc6w-vcg9published:deny_only=trueskipped allow checks and let restricted service accounts mint unrestricted children. Lesson: deny-only logic must never become implicit allow for privilege creation.GHSA-mm2q-qcmx-gw4wpublished: leaked service account access keys plus update-without-ownership formed an escalation chain. Lesson: service-account identifiers are security-sensitive because update APIs consume them.
S3 copy, multipart, and upload policy validation
GHSA-mx42-j6wv-px98published:UploadPartCopymissed source authorization and allowed cross-bucket object exfiltration. Lesson: multipart copy must enforce the same source and destination contract asCopyObject.GHSA-wfxj-ph3v-7mjftriage:UploadPartCopychecked source and destination independently but missed destination copy-source policy constraints. Lesson: source read and destination write checks are not sufficient when policy constrains allowed copy sources.GHSA-w5fh-f8xh-5x3ppublished: presigned POST accepted uploads without enforcing signed policy conditions. Lesson: parse and enforce all POST policy constraints server-side, including size, key prefix, and content type.
Filesystem paths and object key traversal
GHSA-pq29-69jg-9mxcpublished: RPCread_file_streamjoined untrusted paths under a volume directory without canonical boundary checks. Lesson:PathBuf::joinplus length checks are not path security.GHSA-8r6f-hmq2-28rgclosed: object keys containing traversal sequences bypassed bucket/object authorization when mapped to filesystem paths. Lesson: reject traversal at object-key parsing and verify final storage paths remain under the expected bucket/key root.
Secrets, defaults, and cryptographic misuse
GHSA-h956-rh7x-ppgjpublished: gRPC used the hard-coded tokenrustfs rpcon both client and server. Lesson: source-visible shared tokens are authentication bypasses.GHSA-r5qv-rc46-hv8qtriage: internode RPC HMAC secret fell back to the public defaultrustfsadmin. Lesson: RPC/internode auth must fail closed instead of silently using public defaults.GHSA-923g-jp7v-f97ftriage: license verification embedded a production RSA private key and used private-key decryption as authenticity. Lesson: ship verifying/public keys only and use real signature verification.
Sensitive logging and debug output
GHSA-r54g-49rx-98crpublished: STS credentials were logged at info level. Lesson: generated credentials must never be logged in plaintext.GHSA-8cm2-h255-v749triage: debug logs leaked session tokens, secret keys, JWT claims, and raw STS response bodies. Lesson: redaction must cover customDebugimplementations and dependency response-body logging.GHSA-333v-68xh-8mmqpublished: invalid RPC signature logging included the shared HMAC secret and expected signature. Lesson: error paths often leak secrets; never log raw secrets or derived authenticators.
RPC input validation and panic safety
GHSA-gw2x-q739-qhcrpublished: malformed gRPCGetMetricspayloads reachedunwrap()on deserialization and caused remote DoS. Lesson: every network/RPC deserialization failure returns an error, not a panic.GHSA-h956-rh7x-ppgjpublished andGHSA-r5qv-rc46-hv8qtriage: weak RPC auth increased reachability of otherwise internal handlers. Lesson: panic bugs become more severe when internode auth is weak or defaulted.
Browser, CORS, and console isolation
GHSA-v9fg-3cr2-277jpublished: object preview rendered attacker-controlled HTML in a same-origin iframe, exposing console credentials stored inlocalStorage. Lesson: user content must be origin-isolated from the console and protected withnosniff, CSP, and strict content-type handling.GHSA-x5xv-223c-8vm7triage: default CORS reflected arbitrary origins with credentials. Lesson: never combine reflected origins withAccess-Control-Allow-Credentials: true; default should be fail-closed.
Trusted proxy and source IP conditions
GHSA-fc6g-2gcp-2qrqpublished:aws:SourceIptrusted client-suppliedX-Forwarded-FororX-Real-IP. Lesson: forwarded IP headers are valid only behind configured trusted proxies; direct clients use socket peer IP.
SSE and on-disk storage invariants
GHSA-xrrf-67jm-3c2rclosed: SSE metadata reported encryption while reader composition bypassedEncryptReaderand stored plaintext. Lesson: test actual bytes on disk and wrapper order, not only API metadata.
Useful Search Seeds
Use these targeted searches when a diff touches security-sensitive code:
rg -n "validate_admin_request|check_permissions|AdminAction::|deny_only|is_allowed" rustfs crates
rg -n "UploadPartCopy|upload_part_copy|CompleteMultipart|PostObject|content-length-range|starts-with" rustfs crates
rg -n "PathBuf::join|canonicalize|\\.\\.|x-forwarded-for|x-real-ip|SourceIp" rustfs crates
rg -n "DEFAULT_SECRET|DEFAULT_ACCESS|TEST_PRIVATE_KEY|rustfs rpc|RUSTFS_RPC_SECRET" rustfs crates
rg -n "debug!|trace!|info!|error!|\\?resp|\\?merged_config|session_token|secret_key" rustfs crates
rg -n "HashReader|EncryptReader|SSE|server-side encryption|Access-Control-Allow-Credentials|Origin" rustfs crates
Minimum Regression Test Expectations
- Authz fixes: include unauthenticated, valid low-privilege, wrong-action, correct-action, owner, non-owner, and root/admin cases as applicable.
- IAM fixes: include import/update/list service-account cases with attacker-controlled parent, claims, access key, secret key, and policy.
- Copy/upload fixes: include cross-bucket, cross-user, source-denied, destination-denied, copy-source-condition, and multipart completion cases.
- Path fixes: include encoded traversal, absolute path, nested traversal, valid object keys that resemble traversal text but should be rejected, and canonical boundary checks.
- Logging fixes: assert redacted output for structs and response bodies that may contain credentials.
- Browser/CORS fixes: assert no credentials on reflected/default origins, correct behavior for explicit allowlists, and no same-origin script execution for previewed object content.
- SSE fixes: inspect stored bytes and verify API metadata, read-back behavior, and on-disk ciphertext together.