The vendor explicitly identifies these products as affected by this CVE.
- cryostat/cryostat-storage-rhel9 as a component of Cryostat 4
- Summary
- A flaw was found in SeaweedFS. An authenticated remote attacker with write access to a single bucket could exploit a path traversal vulnerability in the S3 gateway. By crafting a DeleteObjects XML request body with specific object keys containing directory traversal sequences, the attacker could bypass authorization controls. This allows the attacker to delete arbitrary objects in other tenants' buckets, leading to unauthorized data deletion.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the criteria for vulnerability selection or Red Hat Product Security recommendation. Restricting S3 write access to trusted principals reduces the risk of exploitation.
