SB2022062922 - Improper Authorization in minio.io minio
Published: March 8, 2021 Updated: June 29, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2021-21362)
The vulnerability allows a remote user to modify files on the system.
The vulnerability exists due to improper authorization error in MinIO. A remote user can bypass a readOnly policy by creating a temporary 'mc share upload' URL.
Remediation
Install update from vendor's website.