Minio

Minio

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 28.05.2024 19:15:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by sending a random object name requests can be used to determin...

Exploit
  • EPSS 27.06%
  • Veröffentlicht 31.01.2024 22:15:54
  • Zuletzt bearbeitet 21.11.2024 08:59:36

MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, th...

  • EPSS 0.64%
  • Veröffentlicht 22.03.2023 21:15:18
  • Zuletzt bearbeitet 21.11.2024 07:55:03

Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user...

Warnung Exploit
  • EPSS 52.09%
  • Veröffentlicht 22.03.2023 21:15:18
  • Zuletzt bearbeitet 26.02.2026 15:03:51

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out t...

Warnung Exploit
  • EPSS 94%
  • Veröffentlicht 22.03.2023 21:15:18
  • Zuletzt bearbeitet 24.10.2025 14:46:55

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSW...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 14.03.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:53:12

Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `consoleAdmin` permissions can potentially create a user that matches the root credential `accessKey`. ...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 21.02.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:50:14

Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all users attempting to DELETE a versionId with the special header `X-Amz-B...

Exploit
  • EPSS 8.28%
  • Veröffentlicht 01.08.2022 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:11:57

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the...

Exploit
  • EPSS 1.37%
  • Veröffentlicht 07.06.2022 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:44

MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due t...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 12.04.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:51:13

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their acc...