Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21362

Опубликовано: 08 мар. 2021
Источник: nvd
CVSS3: 7.7
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc share upload' URL. Everyone is impacted who uses MinIO multi-users. This is fixed in version RELEASE.2021-03-04T00-53-13Z. As a workaround, one can disable uploads with Content-Type: multipart/form-data as mentioned in the S3 API RESTObjectPOST docs by using a proxy in front of MinIO.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
Версия до 2021-03-04t00-53-13z (исключая)

EPSS

Процентиль: 29%
0.00103
Низкий

7.7 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-285
CWE-863

Связанные уязвимости

CVSS3: 6.5
redhat
почти 5 лет назад

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc share upload' URL. Everyone is impacted who uses MinIO multi-users. This is fixed in version RELEASE.2021-03-04T00-53-13Z. As a workaround, one can disable uploads with `Content-Type: multipart/form-data` as mentioned in the S3 API RESTObjectPOST docs by using a proxy in front of MinIO.

CVSS3: 7.7
debian
почти 5 лет назад

MinIO is an open-source high performance object storage service and it ...

CVSS3: 7.7
fstec
почти 5 лет назад

Уязвимость сервера хранения объектов MinIO, связанная с ошибками авторизации, позволяющая нарушителю обойти политику readOnly и оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 29%
0.00103
Низкий

7.7 High

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-285
CWE-863