Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43858

Опубликовано: 27 дек. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Средний

Описание

MinIO is a Kubernetes native application for cloud storage. Prior to version RELEASE.2021-12-27T07-23-18Z, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version RELEASE.2021-12-27T07-23-18Z changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit Deny rule to disable the API for users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*
Версия до 2021-12-27t07-23-18z (исключая)

EPSS

Процентиль: 98%
0.53117
Средний

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-269
CWE-863

Связанные уязвимости

CVSS3: 8.8
redhat
около 4 лет назад

MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.

CVSS3: 8.8
debian
около 4 лет назад

MinIO is a Kubernetes native application for cloud storage. Prior to v ...

CVSS3: 8.8
fstec
около 4 лет назад

Уязвимость сервера хранения объектов MinIO, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 98%
0.53117
Средний

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-269
CWE-863