BIT-seaweedfs-2026-72920

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/seaweedfs/BIT-seaweedfs-2026-72920.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-seaweedfs-2026-72920
Aliases
Published
2026-08-17T05:54:16Z
Modified
2026-09-10T15:26:01Z
Summary
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
Details

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:go:*:*"
    ],
    "severity":  "Critical"
}
References

Affected packages

Bitnami / seaweedfs

Package

Name
seaweedfs
Purl
pkg:bitnami/seaweedfs

Severity

  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.24.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/seaweedfs/BIT-seaweedfs-2026-72920.json"