3 ms·
RustFS hardcoded auth token CVE (9.8)
- xendo 9mo agoSeems they have already removed > RustFS is written in Rust, a memory-safe language, so it is 100% secure From their docs. https://github.com/rustfs/docs.rustfs.com/commit/cd1ece3c5f5f3387eed59a8fb02bc55ace7bed5c#diff-bcdf056b6137f1ee40bd3bb74dc8ae2f9812817c37f349c3a3331f6db05f53a2L25 https://github.com/rustfs/docs.rustfs.com/commit/cd1ece3c5f5...
- pkhuong 9mo agoFix (creation of the rustfs-credentials crate) smuggled in a fairly large panic fix PR https://github.com/rustfs/rustfs/pull/1291#:~:text=Fixes%20CVE%2DXXXX%2DXXXX%20RustFS%20gRPC%20GetMetrics%20deserialization%20panic%20enables%20remote%20DoS https://github.com/rustfs/rustfs/pull/1291#:~:text=Fixes%20C... , "fix: Prevent panic in GetMetrics gRPC handler on invalid input"