SB2021031308 - Arch Linux update for minio
Published: March 13, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2021-21362)
The vulnerability allows a remote user to modify files on the system.
The vulnerability exists due to improper authorization error in MinIO. A remote user can bypass a readOnly policy by creating a temporary 'mc share upload' URL.
Remediation
Install update from vendor's website.