Database/Control plane, storage & DevOps
MinIO (IAM policy engine): A regular user can step outside the policy restrictions applied to them, reaching operations
CVSS 8.8CVE-2021-41137Control plane, storage & DevOpscurated
Impact
A regular user can step outside the policy restrictions applied to them, reaching operations and objects the policy was written to deny. The bucket policy you rely on to keep tenants apart stops being a boundary.
Who can reach it
Any authenticated MinIO user with network access to the S3 endpoint.
What to do
Upgrade to RELEASE.2021-10-10T16-53-30Z or later and restart the cluster. Re-verify tenant separation with an explicit access test per bucket rather than assuming the policy document is being honoured.
References
Related entries
- MinIO: Hand-crafted admin API call updates a user's policyCVE-2021-43858 · MinIOHigh
- Samba (SMB gateway): Out-of-bounds heap read/write in vfs_fruitCVE-2021-44142 · Samba (SMB gateway)High
- HTCondor (SciTokens authentication): A SciToken is granted more authorization than the token's scopes should permit.CVE-2021-45102 · HTCondor (SciTokens authentication)High
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateCVE-2022-1552 · PostgreSQLHigh
- Samba (AD DC): KDC and kpasswd share keysCVE-2022-2031 · Samba (AD DC)High
- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerCVE-2022-23182 · Intel Data Center ManagerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.