Количество 6
Количество 6
CVE-2026-42600
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
CVE-2026-42600
MinIO is a high-performance object storage system. From RELEASE.2022-0 ...
ROS-20260831-80-0010
Уязвимость minio
ROS-20260831-73-0008
Уязвимость minio
GHSA-xh8f-g2qw-gcm7
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
BDU:2026-14529
Уязвимость функции ReadMultiple() компонента Storage REST API сервера хранения объектов MinIO, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-42600 MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z. | CVSS3: 4.9 | 9% Низкий | 4 месяца назад | |
CVE-2026-42600 MinIO is a high-performance object storage system. From RELEASE.2022-0 ... | CVSS3: 4.9 | 9% Низкий | 4 месяца назад | |
ROS-20260831-80-0010 Уязвимость minio | CVSS3: 4.9 | 9% Низкий | 18 дней назад | |
ROS-20260831-73-0008 Уязвимость minio | CVSS3: 4.9 | 9% Низкий | 18 дней назад | |
GHSA-xh8f-g2qw-gcm7 MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint | CVSS3: 4.9 | 9% Низкий | 4 месяца назад | |
BDU:2026-14529 Уязвимость функции ReadMultiple() компонента Storage REST API сервера хранения объектов MinIO, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 4.9 | 9% Низкий | 5 месяцев назад |
Уязвимостей на страницу