GHSA-2v6v-25fm-p4fg

    Dashboard / Vulnerabilities / GHSA-2v6v-25fm-p4fg

    GHSA-2v6v-25fm-p4fg

    Published: 2 Sept 2026Last Modified: 10 Sept 2026

    Summary: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

    Details: ### Impact The filer registered the IAM gRPC service (`SeaweedIdentityAccessManagement`) with no authentication. Any client able to reach the filer gRPC port could invoke IAM RPCs — `CreateUser`, `CreateAccessKey`, `PutUserPolicy`, and related calls — to mint credentials and grant itself S3 administrative privileges. This fully compromises the confidentiality, integrity, and availability of stored objects. No credentials are required, and enabling the documented JWT signing keys does not close it: the IAM gRPC service was not gated by that mechanism. Even under mTLS, the listener-level `allowed_commonNames` ACL applies to the port rather than to individual RPCs, so any cluster mesh certificate could reach these administrative calls. ### Affected component - `weed/server/filer_server_handlers_iam_grpc.go` - `weed/command/filer.go` ### Patches Fixed in **4.24**. Every IAM RPC now requires a Bearer token signed with the filer admin signing key (`jwt.filer_signing.key`), and the service refuses to register when no signing key is configured — removing the unauthenticated default entirely. ### Workarounds Restrict the filer gRPC port to trusted hosts. Configure `jwt.filer_signing.key` in `security.toml` and upgrade to 4.24; operators that use the IAM RPCs must attach an admin-signed Bearer token on each call. ### References - Fixed by seaweedfs/seaweedfs#9442 (follow-ups: #9498, #9508, #9514, #9536) - Reported by Kadir Arslan (https://github.com/KadirArslan)

    Affected packages

    Package

    Name: github.com/seaweedfs/seaweedfs

    Purl: pkg:golang/github.com/seaweedfs/seaweedfs

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.0.0-20260512171108-5e8f99f40a8a

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-2v6v-25fm-p4fg | CVE-DB