← Späť na vyhľadávanie CVE

CVE-2026-79787

Alluxio

Popis

Alluxio-s S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

CVSS 9.8EPSS 0.347%Riziko 1.01
Zobraziť zdroj
Zverejnené
2026-08-25 19:16:54
Dotknuté verzie
unknown
Typ
Webová aplikácia
Posledná úprava
2026-08-25 19:16:54
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H