← Zurück zur CVE-Suche

CVE-2026-79787

Alluxio

Beschreibung

Alluxio-s S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

CVSS 9.8EPSS 0.347%Risiko 1.01
Quelle öffnen
Veröffentlicht
2026-08-25 19:16:54
Betroffene Versionen
unknown
Typ
Webanwendung
Zuletzt geändert
2026-08-25 19:16:54
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H