SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths — GHSA-GV5W-HFX8-8CWQ
GitHub · GitHub · GHSA-GV5W-HFX8-8CWQ
ID
GHSA-GV5W-HFX8-8CWQ
GHSA-GV5W-HFX8-8CWQ
Datum
Quelle
GitHub
GitHub
Vendor
GitHub
GitHub
Risiko
hoch
hoch
CVSS
8.1
8.1
EPSS
0.00238
0.00238
Zusammenfassung
### Impact When a filer JWT restricts a token to a set of path prefixes via `allowed_prefixes`, the authorization check used a literal byte-prefix match (`strings.HasPrefix`). A token scoped to `/tenant1` therefore also authorized requests to sibling paths such as `/tenant1234`, `/tenant1-old`, and `/tenant1backup`. In a multi-tenant deployment this lets the holder of one tenant's token access another tenant's…
Zeitlicher Verlauf
- Von der Quelle veröffentlicht
- 2026-09-02
Risikokontext
- Gemeldeter Schweregrad oder Risikowert: hoch.
- Gemeldeter CVSS-Wert: 8.1 von 10.
- Gemeldeter EPSS-Wert: 0.00238.
- Prüfe die Exponierung für das betroffene Produkt oder die Produktfamilie: go: github.com/seaweedfs/seaweedfs.
Produkt
go: github.com/seaweedfs/seaweedfs
Was tun?
Allgemeine, vorsichtige Schritte (bitte prüfe die offizielle Quelle für Details):
- Priorisiere sofort Patches oder Mitigations (hohes akutes Risiko).
- Identifiziere betroffene Produktversionen und prüfe, ob du betroffen bist.
- Spiele Hersteller-Updates/Patches ein oder setze empfohlene Mitigations um.
- Lies das offizielle Advisory für betroffene Versionen und konkrete Schritte.
Offizielles Advisory
Nachweise und Herkunft
- Kanonische Advisory-ID
- GHSA-GV5W-HFX8-8CWQ
- Quelle
- GitHub
- Vendor
- GitHub
- Von der Quelle veröffentlicht
- 2026-09-02
- Letzte Quellenaktivität
- 2026-09-02
- Weitere Kennungen
- CVE-2026-72921
- Kuratiert von
- hlukh.ch
Verwandte Hinweise und Zusammenhänge
Diese Hinweise sind anhand gemeinsamer CVE-, Produkt-, Hersteller-, Quellen- oder Zeitsignale verknüpft.