Описание
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.
In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. Attackers could craft malicious XML inputs to extract sensitive data from the system's properties or environment variables, potentially compromising security in applications relying on minio-java for object storage operations.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | io.minio/minio | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | minio | Affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | io.minio/minio | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | minio | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | io.minio/minio | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | minio | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | io.minio/minio | Not affected | ||
| Red Hat build of Apache Camel 4.10.7 for Spring Boot 3.4.10 | io.minio/minio | Fixed | RHSA-2025:18028 | 14.10.2025 |
| Red Hat build of Apache Camel 4.10.7 for Spring Boot 3.4.10 | minio | Fixed | RHSA-2025:18028 | 14.10.2025 |
| Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 | io.minio/minio | Fixed | RHSA-2025:19095 | 23.10.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system properties or environment variables were automatically substituted with their actual values during processing. This unintended behavior could lead to the exposure of sensitive information, including credentials, file paths, or system configuration details, if such references were present in XML content from untrusted sources. This is fixed in version 8.6.0.
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform ...
EPSS
7.5 High
CVSS3