Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-21362

Опубликовано: 18 мар. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc share upload' URL. Everyone is impacted who uses MinIO multi-users. This is fixed in version RELEASE.2021-03-04T00-53-13Z. As a workaround, one can disable uploads with Content-Type: multipart/form-data as mentioned in the S3 API RESTObjectPOST docs by using a proxy in front of MinIO.

A flaw has been identified in minio (https://github.com/minio/minio). It is possible to bypass a readOnly policy by creating a temporary 'mc share upload'.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/cert-policy-controller-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/clusterlifecycle-state-metrics-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/config-policy-controller-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/endpoint-monitoring-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/governance-policy-propagator-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/governance-policy-spec-sync-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/governance-policy-status-sync-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/governance-policy-template-sync-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/iam-policy-controller-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicloud-manager-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1980408minio: Allows bypassing readOnly policy by creating a temporary 'mc share upload' URL

EPSS

Процентиль: 29%
0.00103
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
почти 5 лет назад

MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly policy by creating a temporary 'mc share upload' URL. Everyone is impacted who uses MinIO multi-users. This is fixed in version RELEASE.2021-03-04T00-53-13Z. As a workaround, one can disable uploads with `Content-Type: multipart/form-data` as mentioned in the S3 API RESTObjectPOST docs by using a proxy in front of MinIO.

CVSS3: 7.7
debian
почти 5 лет назад

MinIO is an open-source high performance object storage service and it ...

CVSS3: 7.7
fstec
почти 5 лет назад

Уязвимость сервера хранения объектов MinIO, связанная с ошибками авторизации, позволяющая нарушителю обойти политику readOnly и оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 29%
0.00103
Низкий

6.5 Medium

CVSS3