Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-31489

Опубликовано: 03 апр. 2025
Источник: redhat
CVSS3: 7.5

Описание

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which would mean that as a client you can use any arbitrary secret to upload objects given the user already has prior WRITE permissions on the bucket. Prior knowledge of access-key, and bucket name this user might have access to - and an access-key with a WRITE permissions is necessary. However with relevant information in place, uploading random objects to buckets is trivial and easy via curl. This issue is fixed in RELEASE.2025-04-03T14-56-28Z.

A flaw was found in the Minio package. The signature component of the authorization may be invalid, which would mean that, as a client, you can use any arbitrary secret to upload objects, given the user already has prior WRITE permissions on the bucket. Prior knowledge of the access key and bucket name this user might have access to is necessary, and an access key with WRITE permissions is necessary. However, with relevant information in place, uploading random objects to buckets is trivial and easy via curl.

Меры по смягчению последствий

To mitigate this issue, reject requests with x-amz-content-sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER for now at the LB layer. Ask application users to use STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Network Observability Operatornetwork-observability/network-observability-operator-bundleNot affected
Network Observability Operatornetwork-observability/network-observability-rhel9-operatorNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-api-server-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-artifact-manager-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-cache-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-persistenceagent-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-scheduledworkflow-containerNot affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-gateway-opa-rhel8Not affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-gateway-rhel8Not affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-jaeger-query-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2357275minio: MinIO performs incomplete signature validation for unsigned-trailer uploads

7.5 High

CVSS3

Связанные уязвимости

nvd
5 месяцев назад

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which would mean that as a client you can use any arbitrary secret to upload objects given the user already has prior WRITE permissions on the bucket. Prior knowledge of access-key, and bucket name this user might have access to - and an access-key with a WRITE permissions is necessary. However with relevant information in place, uploading random objects to buckets is trivial and easy via curl. This issue is fixed in RELEASE.2025-04-03T14-56-28Z.

debian
5 месяцев назад

MinIO is a High Performance Object Storage released under GNU Affero G ...

github
5 месяцев назад

MinIO performs incomplete signature validation for unsigned-trailer uploads

7.5 High

CVSS3