PT-2024-5523 · Minio+2 · Minio+2

Stefansundin

·

Published

2024-05-28

·

Updated

2024-12-18

·

CVE-2024-36107

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MinIO versions prior to RELEASE.2024-05-27T19-17-46Z
Description The issue concerns the use of If-Modified-Since and If-Unmodified-Since headers with anonymous requests, allowing an attacker to determine if an object exists on the server in a specific bucket and gain access to information such as Last-Modified, Etag, x-amz-version-id, Expires, and Cache-Control metadata values. This conditional check was being honored before validating anonymous access, leading to potential information disclosure.
Recommendations For MinIO versions prior to RELEASE.2024-05-27T19-17-46Z: Upgrade to RELEASE.2024-05-27T19-17-46Z to fix the issue. As a temporary workaround, consider restricting anonymous access to metadata of objects to minimize the risk of exploitation. Avoid using the If-Modified-Since and If-Unmodified-Since headers with anonymous requests until the issue is resolved.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16774
ALT-PU-2024-16866
ALT-PU-2024-17000
BDU:2024-06172
BIT-MINIO-2024-36107
CVE-2024-36107
GHSA-95FR-CM4M-Q5P9
GO-2024-2886

Affected Products

Alt Linux
Minio
Red Os