Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 19:16
Updated : 2026-08-25 19:16
NVD link : CVE-2026-79787
Mitre link : CVE-2026-79787
CVE.ORG link : CVE-2026-79787
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
