RustFS hardcoded auth token CVE (9.8)nvd.nist.gov 4 pointsxendo8 months ago2 commentsSaveHideCopy link On HNComments−pkhuong8moFix (creation of the rustfs-credentials crate) smuggled in a fairly large panic fix PR https://github.com/rustfs/rustfs/pull/1291#:~:text=Fixes%20C... , "fix: Prevent panic in GetMetrics gRPC handler on invalid input"−xendoOP8moSeems they have already removedRustFS is written in Rust, a memory-safe language, so it is 100% secureFrom their docs.https://github.com/rustfs/docs.rustfs.com/commit/cd1ece3c5f5...
Comments
Fix (creation of the rustfs-credentials crate) smuggled in a fairly large panic fix PR https://github.com/rustfs/rustfs/pull/1291#:~:text=Fixes%20C... , "fix: Prevent panic in GetMetrics gRPC handler on invalid input"
Seems they have already removed
From their docs.
https://github.com/rustfs/docs.rustfs.com/commit/cd1ece3c5f5...