Improper Authorization in minio.io minio



Published: 2021-03-08 | Updated: 2022-06-29
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2021-21362
CWE-ID CWE-285
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
minio
Other software / Other software solutions

Vendor minio.io

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper Authorization

EUVDB-ID: #VU64791

Risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-21362

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: No

Description

The vulnerability allows a remote user to modify files on the system.

The vulnerability exists due to improper authorization error in MinIO. A remote user can bypass a readOnly policy by creating a temporary 'mc share upload' URL.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

minio: 2020-01-03T19-12-21Z - 2021-03-01T04-20-55Z

External links

http://github.com/minio/minio/commit/039f59b552319fcc2f83631bb421a7d4b82bc482
http://github.com/minio/minio/pull/11682
http://github.com/minio/minio/releases/tag/RELEASE.2021-03-04T00-53-13Z
http://github.com/minio/minio/security/advisories/GHSA-hq5j-6r98-9m8v


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###