PT-2022-23025 · Minio+1 · Minio+1
Alevsk
·
Published
2022-07-29
·
Updated
2024-12-26
·
CVE-2022-35919
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MinIO (affected versions not specified)
Description
The issue affects MinIO, a High Performance Object Storage, where
admin users authorized for admin:ServerUpdate can trigger an error that returns the content of the requested path. This allows access to contents at arbitrary paths readable by the MinIO process.Recommendations
For all affected versions, users are advised to upgrade.
As a temporary workaround, consider disabling the ServerUpdate API by denying the
admin:ServerUpdate action for admin users via IAM policies.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Minio